Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New ForumTroll Phishing Attacks Target Russian Scholars Using Fake eLibrary Emails

New ForumTroll Phishing Attacks Target Russian Scholars Using Fake eLibrary Emails

Posted on December 17, 2025December 17, 2025 By CWS

Dec 17, 2025Ravie LakshmananVulnerability / Malware

The risk actor linked to Operation ForumTroll has been attributed to a recent set of phishing assaults focusing on people inside Russia, in keeping with Kaspersky.
The Russian cybersecurity vendor mentioned it detected the brand new exercise in October 2025. The origins of the risk actor are presently unknown.
“Whereas the spring cyberattacks centered on organizations, the autumn marketing campaign honed in on particular people: students within the subject of political science, worldwide relations, and international economics, working at main Russian universities and analysis establishments,” safety researcher Georgy Kucherin mentioned.
Operation ForumTroll refers to a collection of subtle phishing assaults exploiting a then-zero-day vulnerability in Google Chrome (CVE-2025-2783) to ship the LeetAgent backdoor and a adware implant generally known as Dante.
The most recent assault wave additionally commences with emails that claimed to be from eLibrary, a Russian scientific digital library, with the messages despatched from the tackle “assist@e-library[.]wiki.” The area was registered in March 2025, six months earlier than the beginning of the marketing campaign, suggesting that preparations for the assault had been underway for a while.

Kaspersky mentioned the strategic area getting older was completed to keep away from elevating any pink flags sometimes related to sending emails from a freshly registered area. As well as, the attackers additionally hosted a replica of the legit eLibrary homepage (“elibrary[.]ru”) on the bogus area to keep up the ruse.

The emails instruct potential targets to click on on an embedded hyperlink pointing to the malicious website to obtain a plagiarism report. Ought to a sufferer observe by way of, a ZIP archive with the naming sample “__.zip” is downloaded to their machine.
What’s extra, these hyperlinks are designed for one-time use, that means any subsequent makes an attempt to navigate to the URL trigger it to show a Russian language message stating “Obtain failed, please attempt once more later.” Within the occasion, the obtain is tried from a platform aside from Home windows, the consumer is prompted to “attempt once more afterward a Home windows laptop.”
“The attackers additionally fastidiously personalised the phishing emails for his or her targets, particular professionals within the subject,” the corporate mentioned. “The downloaded archive was named with the sufferer’s final title, first title, and patronymic.”

The archive accommodates a Home windows shortcut (LNK) with the identical title, which, when executed, runs a PowerShell script to obtain and launch a PowerShell-based payload from a distant server. The payload then contacts a URL to fetch a final-stage DLL and persist it utilizing COM hijacking. It additionally downloads and shows a decoy PDF to the sufferer.
The ultimate payload is a command-and-control (C2) and pink teaming framework generally known as Tuoni, enabling the risk actors to realize distant entry to the sufferer’s Home windows system.
“ForumTroll has been focusing on organizations and people in Russia and Belarus since not less than 2022,” Kaspersky mentioned. “Given this prolonged timeline, it’s probably this APT group will proceed to focus on entities and people of curiosity inside these two international locations.”
The disclosure comes as Optimistic Applied sciences detailed the actions of two risk clusters, QuietCrabs – a suspected Chinese language hacking group additionally tracked as UTA0178 and UNC5221 – and Thor, which seems to be concerned in ransomware assaults since Could 2025.

These intrusion units have been discovered to leverage safety flaws in Microsoft SharePoint (CVE-2025-53770), Ivanti Endpoint Supervisor Cell (CVE-2025-4427 and CVE-2025-4428), Ivanti Join Safe (CVE-2024-21887), and Ivanti Sentry (CVE-2023-38035).
Assaults carried out by QuietCrabs reap the benefits of the preliminary entry to deploy an ASPX net shell and use it to ship a JSP loader that is able to downloading and executing KrustyLoader, which then drops the Sliver implant.
“Thor is a risk group first noticed in assaults in opposition to Russian firms in 2025,” researchers Alexander Badayev, Klimentiy Galkin, and Vladislav Lunin mentioned. “As ultimate payloads, the attackers use LockBit and Babuk ransomware, in addition to Tactical RMM and MeshAgent to keep up persistence.”

The Hacker News Tags:Attacks, eLibrary, Emails, Fake, ForumTroll, Phishing, Russian, Scholars, Target

Post navigation

Previous Post: Microsoft Asks IT Admins to Contact for Fix Related to Windows IIS Failure Issues
Next Post: APT28 Targets Ukrainian UKR-net Users in Long-Running Credential Phishing Campaign

Related Posts

Enhancing Mobile Security with Samsung Knox Enhancing Mobile Security with Samsung Knox The Hacker News
Russian Hacker Jailed for Botnet Ransomware Crimes Russian Hacker Jailed for Botnet Ransomware Crimes The Hacker News
Experts Confirm JS#SMUGGLER Uses Compromised Sites to Deploy NetSupport RAT Experts Confirm JS#SMUGGLER Uses Compromised Sites to Deploy NetSupport RAT The Hacker News
Cybersecurity Stars Awards 2026: 95 Winners Revealed Cybersecurity Stars Awards 2026: 95 Winners Revealed The Hacker News
15,000 Fake TikTok Shop Domains Deliver Malware, Steal Crypto via AI-Driven Scam Campaign 15,000 Fake TikTok Shop Domains Deliver Malware, Steal Crypto via AI-Driven Scam Campaign The Hacker News
New “Brash” Exploit Crashes Chromium Browsers Instantly with a Single Malicious URL New “Brash” Exploit Crashes Chromium Browsers Instantly with a Single Malicious URL The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hundreds of Fake VPN Extensions Divert Browser Traffic
  • Critical VMware vCenter Vulnerability Exploited by Hackers
  • Eclipse Ransomware Unveils Multi-Platform RaaS Targeting Diverse Systems
  • Mindgard Secures $30 Million to Enhance AI Security
  • Global Cyber Campaign Targets Salesforce and ServiceNow

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hundreds of Fake VPN Extensions Divert Browser Traffic
  • Critical VMware vCenter Vulnerability Exploited by Hackers
  • Eclipse Ransomware Unveils Multi-Platform RaaS Targeting Diverse Systems
  • Mindgard Secures $30 Million to Enhance AI Security
  • Global Cyber Campaign Targets Salesforce and ServiceNow

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark