HomeSecurityMem3nt0 Mori hackers use Chrome zero-day

Mem3nt0 Mori hackers use Chrome zero-day

The notorious Mem3nt0 Mori hacker group is at the center of a new high-profile cyberattack exploiting a zero-day vulnerability in Google Chrome ( CVE-2025-2783 ). The flaw, which allowed Chrome's sandbox to be bypassed with minimal user interaction, was used to install sophisticated spyware on targets in Russia and Belarus .

Mem3nt0 Mori Chrome zero-day

The “ForumTroll” operation: Phishing with surgical precision

The attack, uncovered by Kaspersky in March 2025, is part of a wider campaign dubbed ForumTroll. The hackers used targeted phishing emailsthat mimicked official invitations to the research forum “Primakov Readings.”

The messages were perfectly worded in Russian and led victims to deceptive websites, which activated the exploit automatically, without requiring any further interaction, such as downloads or confirmations.

See also: HashiCorp Vault: Vulnerabilities allow DoS attacks and authentication bypass

The attacks targeted journalists, academic institutions, government agencies , and financial institutions — all potential carriers of critical information.

The heart of the exploit: A misunderstanding in Chrome's code

CVE-2025-2783 is located in Mojo communication system , which handles data flow between processes on Windows. The issue resulted from incomplete validation of pseudo-handles (such as the -2 pointer to the current thread), which allowed hackers to copy handles outside the sandbox.

Mem3nt0 Mori hackers use Chrome zero-day

This omission had its roots in old Windows optimizations, giving attackers the ability to execute shellcode within the Chrome process – which could mean complete control of the system.

Google reacted quickly, patching the vulnerability with Chrome update 134.0.6998.177, but by then, the attacks had already spread.

See also: Qilin Ransomware combines Linux payload with BYOVD exploit

Anatomy of an attack: From phishing to spyware

According to Kaspersky, the infection chain included multiple stages:

  1. User Verification – Using WebGPU to detect if the visit came from a real browser and not a sandbox or research environment.
  2. Cryptographic communication – Key exchange via Elliptic-Curve Diffie-Hellman, which decrypted the payload, hidden in JavaScript bundles or fonts.
  3. Execution and persistence – Use of COM hijacking and twinapi.dll mechanisms to hide the infection.
  4. Spyware installation – Final loader that decrypted the LeetAgent malware .

LeetAgent operates as a highly sophisticated spyware , with capabilities to record keystrokes , steal documents , monitor systems , and inject processes . The data was sent via HTTPS to C2 servers on the Fastly.net network , using sophisticated obfuscation techniques.

Connecting to Dante spyware

Kaspersky identified that the LeetAgent code shares common elements with Dante spyware, a commercial product from Memento Labs, the company that emerged from the infamous Hacking Team.

Dante was introduced in 2023 at the ISS World, known for its government surveillance tools, and featured anti-debugging mechanisms, VMProtect , and dynamic API analysis to avoid detection.

See also: Using ClickFix techniques to install NetSupport RAT loaders

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The revelation of this connection shows that commercial spyware continues to end up in APT (Advanced Persistent Threats) groups , despite commitments to “lawful use” from governments and companies.

Mem3nt0 Mori hackers use Chrome zero-day

Reactions and protective measures

Experts warn that the Chrome vulnerability is just the tip of the iceberg. A similar flaw was also found in Firefox (CVE-2025-2857), confirming that attacks on IPC mechanisms are a growing trend.

For user protection:

  • Update Chrome to version 134.0.6998.177 or later.
  • Enable Enhanced Safe Browsing.
  • Monitor for suspicious Base64 files or unusual network activity.
  • Avoid suspicious emails and links, especially in institutional or professional environments.

The message behind Mem3nt0 Mori

The group's name, which in Latin means "remember that you will die," seems to reflect its philosophy: a reminder of the fragility of digital security.
In a world where even the most secure platforms can be compromised, the Mem3nt0 Mori case is a reminder that the game of cat and mouse in cyberspace never ends.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS