Chrome 0-Day Vulnerability Actively Exploited in Attacks by Notorious Hacker

The notorious hacker group Mem3nt0 mori has been actively exploiting a critical zero-day vulnerability in Google Chrome Browser, compromising high-profile targets across Russia and Belarus ( majoratily of the Europe). This flaw, identified as CVE-2025–2783, allowed attackers to bypass Google Chrome Browser’s robust sandbox protections with minimal user interaction, leading to the deployment of sophisticated spyware.
🧩 What Is CVE-2025–2783?
CVE-2025–2783 is a zero-day vulnerability in Google Chrome Browser’s Mojo inter-process communication (IPC) system on Windows. Mojo facilitates communication between different browser components while maintaining sandbox isolation. An error in handle management within Mojo allowed attackers to bypass Google Chrome Browser’s sandbox protections, enabling remote code execution with a single click on a malicious link. This flaw was discovered by Kaspersky’s Global Research and Analysis Team (GReAT) in March 2025 and was promptly patched by Google in version 134.0.6998.177/.178 for Windows.
Exploit in the Wild: Operation ForumTroll
Mem3nt0 mori leveraged CVE-2025–2783 in a campaign dubbed “Operation ForumTroll.” The group sent personalized phishing emails, disguised as invitations to the “Primakov Readings” forum, to targets in Russia and Belarus. Upon clicking the malicious link, victims were redirected to a compromised website that exploited the vulnerability, compromising their systems without any further user interaction. The malware deployed was designed for espionage, capable of logging keystrokes, stealing files, and maintaining persistence within system processes.
🕵️♂️ Targeted Entities
The primary targets of this campaign were high-profile institutions across Russia and Belarus, including:
- Media outlets
- Educational institutions
- Government agencies
- Financial organizations
These sectors are particularly vulnerable due to their reliance on digital communication and the potential value of the information they handle. The sophistication of the attack indicates that it was carried out by an advanced persistent threat (APT) group with substantial resources.
🛡️ Mitigation and Recommendations
Google has released a security patch addressing CVE-2025–2783 in Chrome version 134.0.6998.177/.178 for Windows. Users are strongly advised to update their browsers immediately to protect against this vulnerability. Additionally, organizations should implement the following measures:
- Educate employees about phishing tactics and the risks of unsolicited emails.
- Deploy advanced endpoint detection and response (EDR) solutions to monitor for suspicious activities.
- Regularly update all software to ensure vulnerabilities are patched promptly.
- Implement network segmentation to limit the spread of potential infections.
🔍 Conclusion
The exploitation of CVE-2025–2783 by Mem3nt0 mori underscores the persistent threat posed by sophisticated cyber adversaries. Organizations in Russia, Belarus, and beyond should remain vigilant and proactive in their cybersecurity efforts to defend against such advanced attacks. Regular updates, user education, and robust security practices are essential in mitigating the risks associated with such vulnerabilities.
good article about 0 day
ReplyDelete