ForumTroll Phishing Attacks Target Russian Scholars with Fake eLibrary Emails
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Operation ForumTroll has been attributed to a series of phishing attacks targeting individuals in Russia, particularly scholars in political science, international relations, and global economics. Kaspersky reported that these attacks began in October 2025, focusing on personalized emails that appeared to originate from eLibrary, a legitimate Russian scientific electronic library.
The phishing emails were sent from the address “support@e-library[.]wiki,” a domain that was registered in March 2025, indicating premeditated planning. The emails instructed recipients to download a plagiarism report, leading to a ZIP file that contained a Windows shortcut designed to execute a PowerShell script and download malicious payloads.
This attack leverages a zero-day vulnerability in Google Chrome (CVE-2025-2783) to install the LeetAgent backdoor and a spyware implant known as Dante. The downloaded archive was specifically named with the victim’s personal details, enhancing the deception.
The final payload enables remote access to the victim’s device through a command-and-control framework known as Tuoni. This targeted approach suggests a strategic shift from broader organizational attacks to specific individuals of interest, raising concerns about the ongoing risks faced by scholars and researchers in Russia.
Implications for Users and Organizations
Everyday users and organizations should be aware of the sophisticated nature of these phishing attacks, which utilize personalized tactics to increase their effectiveness. Recognizing the signs of phishing, such as unexpected emails requesting downloads or sensitive information, is crucial.
Organizations should implement robust security measures, including training staff to identify phishing attempts and regularly updating software to mitigate vulnerabilities like CVE-2025-2783. Monitoring for unusual activity on devices and networks can also help detect potential breaches early.
Given the specific targeting of scholars, academic institutions should reinforce their cybersecurity protocols and encourage faculty and staff to verify the authenticity of unexpected communications, especially those requesting sensitive data or downloads.
Key Takeaways
- Be cautious of emails that request downloads or sensitive information, especially from unfamiliar sources.
- Regularly update your software and browsers to protect against known vulnerabilities like CVE-2025-2783.
- Implement training programs for staff to recognize phishing attempts and suspicious communications.
- Monitor your devices and networks for unusual activity that may indicate a breach.
- Verify the authenticity of unexpected emails, particularly those claiming to be from legitimate organizations.
Key Terms & Concepts
- Operation ForumTroll: In this article, Operation ForumTroll refers to a series of phishing attacks targeting Russian scholars using sophisticated tactics.
- CVE-2025-2783: CVE-2025-2783 is a zero-day vulnerability in Google Chrome exploited by attackers to deliver malware.
- LeetAgent: LeetAgent is a backdoor malware used in the phishing attacks linked to Operation ForumTroll.
- Tuoni: Tuoni is a command-and-control framework that allows attackers to gain remote access to compromised devices.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.