Back to News
Market Impact: 0.4

Italian spyware vendor linked to Chrome zero-day attacks

GOOGLGOOG
Cybersecurity & Data PrivacyTechnology & InnovationGeopolitics & WarProduct Launches
Italian spyware vendor linked to Chrome zero-day attacks

A recent report by Kaspersky details Operation ForumTroll, a sophisticated cyberattack that leveraged a Google Chrome zero-day (CVE-2025-2783) to deploy advanced LeetAgent and Dante spyware against Russian financial institutions, government entities, and media. The malware is confidently attributed to Memento Labs, an Italian commercial spyware vendor that emerged from the notorious Hacking Team following its 2019 acquisition by InTheCyber Group. This incident underscores the persistent threat posed by commercial spyware firms and the critical need for immediate patching of zero-day vulnerabilities, which Chrome and Firefox have since addressed.

Analysis

The recent Kaspersky report details Operation ForumTroll, a sophisticated cyberattack leveraging a Google Chrome zero-day vulnerability (CVE-2025-2783) to deploy advanced LeetAgent and Dante spyware. This campaign specifically targeted Russian media outlets, universities, research centers, government organizations, and financial institutions. The malware is confidently attributed to Memento Labs, an Italian commercial spyware vendor formed from the notorious Hacking Team. The attack chain involved phishing emails with malicious links, exploiting the Chrome zero-day for shellcode execution and installing persistent loaders. LeetAgent, a modular spyware, enabled command execution, file operations, keylogging, and data theft, while Dante, sharing code similarities with Hacking Team's RCS, demonstrated advanced surveillance capabilities. This highlights the persistent and evolving threat posed by commercial spyware firms. Google addressed CVE-2025-2783 in Chrome version 134.0.6998.178 on March 26, with Mozilla also patching a related issue in Firefox. While the immediate vulnerability is patched, the incident, reflected in a moderately negative sentiment for GOOGL/GOOG (-0.3), underscores the critical need for continuous security updates and robust defense mechanisms against state-sponsored or commercially available advanced persistent threats.

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo

Market Sentiment

Overall Sentiment

moderately negative

Sentiment Score

-0.50

Ticker Sentiment

GOOG-0.30
GOOGL-0.30

Key Decisions for Investors

  • Investors should monitor the cybersecurity sector for increased demand in advanced threat detection and zero-day exploit mitigation solutions, given the persistent commercial spyware threat.
  • For technology giants like Alphabet (GOOGL/GOOG), assess their ongoing investment in security infrastructure and rapid vulnerability patching processes, as these incidents can impact user trust and regulatory scrutiny.
  • Consider the heightened geopolitical risk associated with cyber warfare and commercial spyware, particularly for entities operating in sensitive sectors or regions, which may necessitate re-evaluating risk premiums.