SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Chrome Zero-Day Exploited to Deliver Italian Memento Labs’ LeetAgent Spyware

Chrome Zero-Day Exploited to Deliver Italian Memento Labs’ LeetAgent Spyware

A zero-day vulnerability in Google Chrome, identified as CVE-2025-2783, was recently exploited in the wild to deliver the LeetAgent spyware. This spyware has been linked to the Italian vendor Memento Labs, previously known as Hacking Team. The vulnerability, a sandbox escape, allowed attackers to by...

Oct 28, 2025By Ankireddy Sai Sandeep Reddy4 min read

A zero-day vulnerability in Google Chrome, identified as CVE-2025-2783, was recently exploited in the wild to deliver the LeetAgent spyware. This spyware has been linked to the Italian vendor Memento Labs, previously known as Hacking Team. The vulnerability, a sandbox escape, allowed attackers to bypass Chrome’s security protections and target organizations in Russia and Belarus. A similar vulnerability, CVE-2025-2857, also impacted Firefox.

Operation ForumTroll

The attacks were part of a campaign named “Operation ForumTroll” and orchestrated by the APT group ForumTroll (also tracked as TaxOff/Team 46/Prosperous Werewolf). This group has been active since at least February 2024 and is known for its proficiency in the Russian language. The campaign targeted various entities, including media outlets, universities, research centers, government organizations, and financial institutions in Russia and Belarus.

The attackers used spear-phishing emails with personalized links to the Primakov Readings forum. When a user clicked on these links using Google Chrome or a Chromium-based browser, the exploit for CVE-2025-2783 was triggered, allowing the attackers to escape the browser’s sandbox and deliver tools developed by Memento Labs.

Technical Details of CVE-2025-2783

The root cause of CVE-2025-2783 lies in the incorrect handle validation within the Mojo Inter-Process Communication (IPC) system on Windows. Attackers manipulated Chrome’s IPC system to transform a pseudo-handle into a valid, usable handle within the browser process. This allowed them to execute arbitrary code with the browser’s privileges, effectively bypassing the sandbox.

LeetAgent and Dante Spyware

The attackers deployed a previously undocumented spyware called LeetAgent, known for using leetspeak in its command structure. LeetAgent is capable of connecting to a command-and-control (C2) server over HTTPS, receiving instructions to perform a range of tasks, including:

  • Running commands using cmd.exe
  • Executing processes
  • Stopping tasks
  • Injecting shellcode
  • Reading and writing files
  • Keylogging and file stealing (targeting documents, spreadsheets, and PDFs)

Kaspersky’s analysis uncovered that LeetAgent was also used to deploy another, more sophisticated spyware named Dante. Dante has code similarities with Hacking Team’s Remote Control Systems (RCS) spyware, leading researchers to attribute it to Memento Labs. Dante employs several techniques to evade detection, including VMProtect obfuscation, anti-debugging checks, and dynamic API resolution.

Tactics, Techniques, and Procedures (TTPs)

The attackers employed various MITRE ATT&CK tactics and techniques in this campaign:

  • TA0001 – Initial Access: Phishing emails were used to lure victims to malicious sites.
  • TA0002 – Execution: The CVE-2025-2783 exploit was used to achieve code execution.
  • TA0003 – Persistence: COM hijacking was used to ensure malware persistence.
  • TA0005 – Defense Evasion: Techniques such as obfuscated files and anti-debugging measures were employed.
  • TA0011 – Command and Control: LeetAgent and Dante connected to C2 servers over HTTPS.
  • TA0009 – Collection: Keylogging and file stealing were used to gather data.
  • TA0010 – Exfiltration: Data was exfiltrated over C2 channels.
  • T1566 – Phishing: Spear-phishing emails were used to deliver malicious links.
  • T1203 – Exploitation for Client Execution: CVE-2025-2783 was exploited to execute code.
  • T1547 – Boot or Logon Autostart Execution: COM hijacking ensured persistent execution.
  • T1027 – Obfuscated Files or Information: Code and data were obfuscated to evade detection.
  • T1071 – Application Layer Protocol: HTTPS was used for C2 communication.
  • T1005 – Data from Local System: Data was collected from local systems.
  • T1041 – Exfiltration Over C2 Channel: Exfiltration occurred over the C2 channel.

Mitigation & Recommendations

To protect against similar attacks, it is crucial to:

  • Update Google Chrome to version 134.0.6998.177 or later to patch CVE-2025-2783.
  • Update Firefox to version 136.0.4 to address CVE-2025-2857.
  • Enable enhanced safe browsing in Chrome to provide additional protection against malicious websites and downloads.
  • Be vigilant against phishing emails, especially those containing personalized links or invitations.
  • Monitor systems for indicators of compromise (IOCs) associated with LeetAgent and Dante spyware.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras
Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

CVE Research

Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

A single operator compromised 14,530+ Dahua cameras across Ukraine and Russia in 35 days, chaining credential brute-force, a CVE-2021-33044/33045 authentication bypass, and P2P relay abuse to plant a persistent backdoor and harvest transferable admin access.

Aug 21, 2026

Open Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF
Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE Research

Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE that allows an unauthenticated attacker to modify or delete public projects and user data by abusing a GraphQL directive. A second high-severity issue, CVE-2026-19650, involves cross-site request forgery in the GraphQL multiplex query handler. This article examines how the critical vulnerability works, the availability of a public proof-of-concept, the potential impact on self-managed instances, the affected versions, and the security updates released to remediate both issues.

Aug 19, 2026

Open No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners
No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

CVE Research

No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

Aug 19, 2026

Open Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies
Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

CVE Research

Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

Aug 19, 2026

Chrome Zero-Day Exploited to Deliver Italian Memento Labs’ LeetAgent S | SecPod