On Monday, researchers at cybersecurity firm Kaspersky published a report identifying a new spyware called Dantethat they say was targeting Windows victims in Russia and neighboring Belarus. The researchers said the Dante spyware is being made by Memento Labs, a Milan-based surveillance technology company formed in 2019 after the acquisition and takeover of early spyware maker Hacking Team by a new owner.
See also: ClayRat spyware turns phones into distribution hubs

Memento Labs CEO Paolo Lezziconfirmed to TechCrunch that the spyware detected by Kaspersky is indeed Memento. In a phone call, Lezzi blamed one of the company’s government customers for the Dante discovery, saying the customer used an outdated version of the spyware for Windows, which will no longer be supported by Memento by the end of the year.
Lezzi, who was not sure which of the company's customers were caught, added that Memento Labs had already asked all of its customers to stop using the Windows malware. He said that Memento had warned customers that Kaspersky had detected Dante spyware infections since December 2024. Memento plans to send a message to all of its customers on Wednesday, again asking them to stop using the Windows spyware.
He also noted that Memento currently only develops spyware for mobile platforms. The company also develops some zero-days—security vulnerabilities in software that are unknown to the manufacturer and can be used to deliver spyware—although it mostly sources its exploits from external developers, according to Lezzi.
See also: Beware: Android Spyware Disguises as Signal and ToTok Add-on

When contacted by TechCrunch, Kaspersky spokesperson Mai Al Akkadid not reveal which government Kaspersky believes is behind the spying campaign, but said it was “someone who was able to use Dante software.”
In its new report, Kaspersky says it has found a group of hackers using the Dante spyware, which it refers to as “ForumTroll,” describing the targeting of individuals with invitations to the Russian politics and economics forum Primakov Readings. Kaspersky said the hackers targeted a wide range of industries in Russia, including media, universities and government organizations.
Kaspersky's discovery of Dante came after the Russian cybersecurity firm detected a "wave" of phishing link attacks that exploited a zero-day in the Chrome browser. Lezzi said the Chrome zero-day was not developed by Memento.
In its report, Kaspersky researchers concluded that Memento “continued to improve” the spyware originally developed by Hacking Team until 2022, when the spyware was “replaced by Dante.” Lezzi admitted that it’s possible that some “elements” or “behaviors” of Memento’s Windows spyware are left over from the spyware developed by Hacking Team.
See also: Apple warns of spyware attacks

A telltale sign that the spyware detected by Kaspersky belonged to Memento was that the developers allegedly left the word "DANTEMARKER" in the spyware's code, a clear reference to the name Dante, which Memento Labs had previously publicly revealed at a surveillance technology conference, according to Kaspersky.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
