HomeSecurityNew ForumTroll Phishing Attacks Target Russian Academics

New ForumTroll Phishing Attacks Target Russian Academics

A threat actor linked to Operation ForumTroll is engaging in a new series of phishing attacks targeting individuals in Russia, according to Kaspersky. The Russian cybersecurity vendor said it detected the new activity in October 2025. The origins of the threat actor are currently unknown.

See also: Phantom Stealer: Phishing attack with ISO images targets Russia

ForumTroll

Operation ForumTroll refers to a series of sophisticated phishing attacks that exploit a vulnerability in Google Chrome (CVE-2025-2783) to deliver the LeetAgent and a spyware implant known as Dante. The latest wave of attacks begins with emails claiming to come from eLibrary, a Russian scientific electronic library, with the messages sent from the address “support@e-library[.]wiki.” The domain was registered in March 2025, six months before the campaign began, suggesting that preparations for the attack had been underway for some time.

Kaspersky said the strategic domain aging was done to avoid raising red flags typically associated with sending emails from a newly registered domain. Additionally, the attackers hosted a copy of the legitimate eLibrary homepage (“elibrary[.]ru”) on the fake domain to perpetuate the scam. The emails instruct potential targets to click on an embedded link that leads to the malicious website to download a plagiarism report.

If a victim follows the process, a ZIP file with the naming pattern “<LastName>_<FirstName>_<Patronymic>.zip” is downloaded to his device. These links are designed for single use, meaning that any subsequent attempt to navigate to the URL will result in a message in Russian stating “Download failed, please try again later.”

See also: Abuse of Paypal for phishing attacks

New ForumTroll Phishing Attacks Target Russian Academics
New ForumTroll Phishing Attacks Target Russian Academics

If the download is attempted from a non-Windows platform, the user is prompted to “try again later on a Windows computer.” The attackers also carefully tailored the phishing emails to their targets, specific professionals in the field.

“The downloaded file had the victim’s first name, last name, first name, and middle name.” The file contains a Windows shortcut (LNK) with the same name, which, when executed, runs a PowerShell script to download and launch a PowerShell-based payload from a remote server. The payload then communicates with a URL to retrieve a final-stage DLL and persist it using COM hijacking.

It also downloads and displays a deceptive PDF to the victim. The final payload is a command and control (C2) and red teaming framework known as Tuoni, allowing threat actors to gain remote access to the victim's Windows device.

The revelation of Operation ForumTroll comes as Positive Technologies analyzed the activities of two threat groups, QuietCrabs – a suspected Chinese hacking group also tracked as UTA0178 and UNC5221 – and Thor, which appears to have been involved in ransomware attacks since May 2025.

See also: ConsentFix: A new variant of the ClickFix phishing attack

New ForumTroll Phishing Attacks Target Russian Academics
New ForumTroll Phishing Attacks Target Russian Academics

The attacks carried out by QuietCrabs exploit initial access to deploy an ASPX web shell and use it to deliver a JSP loader that is capable of downloading and executing KrustyLoader, which then drops the Sliver implant.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS