Also known as: TA558, Jripbot, Facebook, Twitter, Microsoft, tracked as, Morpho
Operation ForumTroll represents a highly sophisticated threat actor whose activities have been traced back at least since 2013 under the monikers Wild Neutron, Jripbot and Morpho as reported by Kaspersky's Global Research and Analysis Team (GReAT). In mid‑March 2025 the group capitalised on an undisclosed zero‑day in Google Chrome (CVE‑2025‑2783) to push a dropper via personalised phishing links that mimicked legitimate government forum communications, specifically targeting Russian political scientists. The dropped payload installs a RAT that maintains stealthy command and control communication through HTTPS endpoints while protecting itself against takedown by encrypting traffic and embedding custom back‑end resilience code. Beyond the Chrome exploit, earlier campaigns utilised compromised Flash Player vulnerabilities and forged certificates from legitimate manufacturers to sign malicious binaries. This multi‑platform strategy allowed ForumTroll to infect a wide range of operating systems, including Windows desktop clients and certain Windows Server deployments, thereby expanding its espionage reach across critical infrastructure providers and high‑profile international corporations such as Apple, Facebook, Twitter and Microsoft. Kaspersky's detection heuristics identified the group’s malware as "Trojan.Win32.JripBot.*" and linked it to a persistent C2 network that uses encrypted command strings (e.g. "La revedere" and "uspeshno") embedded within configuration files. The actor’s operational secrecy—manifested in hardened code signing, dynamic DNS, and careful C2 routing—has enabled sustained infiltration for years while eluding most attribution efforts.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Operation ForumTroll, also called TA558 or Jripbot, is an advanced cyber‑espionage outfit linked to state sponsorship that targets a broad spectrum of public and private actors in several countries, including the U.S., Russia, UAE and Vietnam. The group leverages zero‑day vulnerabilities—most notably CVE‑2025‑2783 in Google Chrome—to deliver custom remote access malware that is signed with stolen certificates, enabling it to evade detection. Its operations aim primarily at gathering political, economic and technological intelligence from government, financial, media and manufacturing sectors.
Goals & Targeting
ForumTroll targets public sector decision‑makers, strategic industries (finance, manufacturing, critical infrastructure), and organizations with valuable geopolitical or commercial information. By exploiting zero‑days and sophisticated phishing campaigns, the group gains early footholds within high‑value target networks to conduct long‑term intelligence gathering. The actor's selection of diverse countries—UAE, Russia, US, Lebanon, Vietnam, Germany, France, Kazakhstan—suggests a global espionage mandate aimed at influencing regional political dynamics and securing economic advantage for an unknown sponsor. Typical victims include government ministries, defense contractors, media houses, universities and tech firms where the adversary anticipates access to policy documents, R&D data, or sensitive transaction records. The strategic objective is primarily intelligence collection rather than sabotage, although the breadth of the group's capabilities indicates readiness for disruptive operations if needed.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
ForumTroll has demonstrated a sustained, low‑profile campaign rhythm from 2013 to 2025, with a notable uptick in March 2025 coinciding with the Chrome zero‑day. The actor consistently employs a kit that delivers dropper malware via compromised websites or phishing emails, and then leverages stolen certificates for execution avoidance. Victim selection spans high‑profile technology firms—Apple, Facebook, Microsoft—as well as defense contractors and academic institutions in multiple continents. Past operations also include targeted ransomware incursions (via WhisperBot) and data exfiltration frameworks similar to the widely known Sunburst technique. Operational tempo remains moderate; Kaspersky reports a gradual expansion of targets rather than large‑scale simultaneous attacks. The use of cross‑country targeting indicates either a centralized command structure or a distributed threat‑operator network that tailors payloads for sector‑specific adversaries.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The primary evidence of a zero‑day exploitation in Google Chrome (CVE‑2025‑2783) and the use of stolen code signing certificates is supported by Kaspersky GReAT releases dated March 2025, giving high confidence to those facts. Attribution remains less certain; while multiple aliases (Wild Neutron, Jripbot, Morpho) are consistently linked, definitive national sponsorship is inferred rather than conclusively proven. Details about persistence mechanisms beyond the RAT and exact command–control protocols are partially inferred from observed patterns, representing moderate confidence with noticeable information gaps requiring further technical analysis.
No campaigns linked yet.
No observed data linked yet.
9
Techniques
45
Tools
0
Campaigns
39
IOCs
0
Observed Data
5
Tactics