The Hacking Team is back/Operation ForumTroll
Phishing link → WebGPU decrypt → Shellcode injection → COM hijack for persistence.
Deploys Dante spyware (successor to RCS(Hacking
Team), now Memento Labs) + custom LeetAgent for keylogging, file theft.
Exploits:
Zero-days CVE-2025-2783 (Chrome sandbox escape) & Phishing link → WebGPU decrypt → Shellcode injection → COM hijack for persistence.
securelist.com/forumtroll-ap…
Oct 27, 2025 · 5:36 AM UTC








