{"id":72147,"date":"2025-11-12T07:36:47","date_gmt":"2025-11-11T23:36:47","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=72147"},"modified":"2025-10-29T13:38:35","modified_gmt":"2025-10-29T05:38:35","slug":"kaspersky-unmasks-dante","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2025\/11\/12\/kaspersky-unmasks-dante\/","title":{"rendered":"Kaspersky unmasks &#8216;Dante&#8217;"},"content":{"rendered":"<p dir=\"ltr\"><strong>Kaspersky Global Research and Analysis Team (GReAT) uncovered evidence linking the HackingTeam successor, Memento Labs, to a new wave of cyberespionage attacks. The discovery stems from an investigation into Operation ForumTroll, an Advanced Persistent Threat (APT) campaign that exploited a zero-day vulnerability in Google Chrome.\u00a0<\/strong><\/p>\n<p dir=\"ltr\">In March 2025, Kaspersky GReAT\u00a0<a href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/kaspersky-discovers-sophisticated-chrome-zero-day-exploit-used-in-active-attacks\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">brought to light<\/a>\u00a0Operation ForumTroll, a sophisticated cyberespionage campaign exploiting a Chrome zero-day vulnerability, CVE-2025-2783. The APT group behind the attack sent personalized phishing emails disguised as invitations to the Primakov Readings forum, targeting Russian media outlets,\u00a0government organizations,\u00a0educational\u00a0and financial\u00a0institutions.<\/p>\n<p dir=\"ltr\">While investigating ForumTroll, researchers identified that the attackers used a spyware LeetAgent, which stood out due to its commands written in leetspeak, a rare feature in APT malware. Further analysis uncovered similarities between its toolset and a more advanced spyware that Kaspersky GReAT has observed in other attacks. After determining that, in some cases, the latter was launched by\u00a0LeetAgent\u00a0or that they shared a loader framework, researchers confirmed the connection between the two, as well as between the attacks.<\/p>\n<p dir=\"ltr\">Although the other spyware employed advanced anti-analysis techniques, including\u00a0VMProtect obfuscation, Kaspersky retrieved the malware\u2019s name from the code and identified it as\u00a0Dante. The researchers discovered that a commercial spyware with the same name was promoted by Memento Labs, the rebranded successor to HackingTeam. Additionally, the most recent samples of HackingTeam&#8217;s Remote Control System spyware, obtained by Kaspersky GReAT, share similarities with\u00a0Dante.<\/p>\n<p dir=\"ltr\">\u201cWhile the existence of spyware vendors is well-known in the industry, their products remain elusive, particularly in targeted attacks where identification is exceptionally challenging. Uncovering Dante origin demanded peeling back layers of heavily obfuscated code, tracing a handful of rare fingerprints across years of malware evolution, and correlating them with a corporate lineage. Maybe it is the reason they called it Dante, there is a hell of a journey for anyone who would try to find its roots\u201d,\u00a0said Boris Larin, principal security researcher at Kaspersky GReAT.<\/p>\n<p dir=\"ltr\">To avoid detection,\u00a0Dante\u00a0incorporates a unique way of analyzing its environment before determining whether it can safely carry out its functions.<\/p>\n<p dir=\"ltr\">The researchers traced the first use of\u00a0LeetAgent\u00a0back to\u00a02022\u00a0and discovered additional attacks by\u00a0ForumTroll APT\u00a0targeting organizations and individuals in\u00a0Russia and Belarus. The group stands out for its strong command of\u00a0Russian\u00a0and knowledge of local nuances, traits that Kaspersky observed in other campaigns linked to this APT threat. However, occasional errors suggest that the attackers were not native speakers.<\/p>\n<p dir=\"ltr\">The attack leveraging LeetAgent was first detected by\u00a0<a href=\"https:\/\/www.kaspersky.com\/enterprise-security\/xdr\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Kaspersky Next XDR Expert<\/a>. The full details of this research, as well as future updates on ForumTroll APT and Dante, are available to customers of the APT reporting service through\u00a0<a href=\"https:\/\/opentip.kaspersky.com\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Kaspersky Threat Intelligence Portal<\/a>.<\/p>\n<p dir=\"ltr\">For more details and indicators of compromise, see the article on\u00a0<a href=\"https:\/\/securelist.com\/forumtroll-apt-hacking-team-dante-spyware\/117851\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Securelist.com.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>While investigating ForumTroll, researchers identified that the attackers used a spyware LeetAgent, which stood out due to its commands written in leetspeak, a rare feature in APT malware.<\/p>\n","protected":false},"author":6,"featured_media":72148,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[101,54],"class_list":["post-72147","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-kaspersky","tag-security"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/72147","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=72147"}],"version-history":[{"count":1,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/72147\/revisions"}],"predecessor-version":[{"id":72149,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/72147\/revisions\/72149"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/72148"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=72147"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=72147"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=72147"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}