Operation ForumTroll

First seen
2025-03-15 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:21:08

Targeted industries: media-and-entertainment education-and-nonprofits government-and-public-sector

Targeted regions: country_code:ru

Context

Operation ForumTroll is a sophisticated cyber espionage campaign discovered by Kaspersky in mid-March 2025. The attack exploited a zero-day vulnerability in Google Chrome, identified as CVE-2025-2783, which allowed attackers to bypass the browser's security features. Victims were infected by clicking on personalized phishing links in emails, allegedly from the organizers of the "Primakov Readings" forum, targeting media outlets, educational institutions, and government organizations in Russia. The goal of the attack appears to be espionage, and the campaign is believed to be the work of a state-sponsored APT group. Google quickly released an update to fix the vulnerability after being notified by Kaspersky.

Exploited vulnerabilities

  • CVE-2025-2783 (vulnerability)

Reports & references

  • Kaspersky — 115989 (report)

External references