Chrome Zero-Day Exploited to Deliver Italian Memento Labs’ LeetAgent Spyware

According to recent Kaspersky discoveries, an espionage-related tool from Italian information technology and services business Memento Labs was distributed as a result of the zero-day exploitation of a now-patched security hole in Google Chrome.

The business revealed in March 2025 that the sandbox escape vulnerability, CVE-2025-2783 (CVSS score: 8.3), was being actively exploited as part of a campaign called Operation ForumTroll that targeted Russian organizations. Additionally, BI.ZONE tracks the cluster as Prosperous Werewolf and Positive Technologies tracks it as TaxOff/Team 46. Since at least February 2024, it has been known to be operational.

Phishing emails with customized, transient links inviting recipients to the Primakov Readings forum were used in the wave of infections. It was sufficient to click the URLs using Google Chrome or a Chromium-based web browser to initiate an exploit for CVE-2025-2783, which allowed the attackers to escape the program’s limitations and distribute Memento Labs tools.

Following the merging of InTheCyber Group and HackingTeam (commonly known as Hacking Team), Memento Labs (sometimes styled as mem3nt0) was established in April 2019 with its headquarters located in Milan read more about Chrome Zero-Day Exploited to Deliver Italian Memento Labs’ LeetAgent Spyware.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *