{"id":31517,"date":"2025-12-17T04:45:26","date_gmt":"2025-12-17T04:45:26","guid":{"rendered":"http:\/\/localhost\/?p=31517"},"modified":"2025-12-17T04:45:26","modified_gmt":"2025-12-17T04:45:26","slug":"operation-forumtroll-continues-russian-political-scientists-targeted-using-plagiarism-reports","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=31517","title":{"rendered":"Operation ForumTroll continues: Russian political scientists targeted using plagiarism reports_SECURELIST:E7FB3FBADAF7528523707FFB60591D8A"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-12-17T10:05:09&#8243;,&#8221;description&#8221;:&#8221;![](https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2025\/12\/17093749\/forumtroll-part-3-featured-image-990&#215;400.jpg)\\n\\n## Introduction\\n\\nIn March 2025, we discovered Operation ForumTroll, a series of sophisticated cyberattacks exploiting the CVE-2025-2783 vulnerability in Google Chrome. We previously detailed the malicious implants used in the operation: the LeetAgent backdoor and the complex spyware Dante, developed by Memento Labs (formerly Hacking Team). However, the attackers behind this operation didn&#8217;t stop at their spring campaign and have continued to infect targets within the Russian Federation.\\n\\n## Emails posing as a scientific library\\n\\nIn October 2025, just days before we presented our report detailing the ForumTroll APT group&#8217;s attack at the Security Analyst Summit, we detected a new targeted phishing campaign by the same group. However, while the spring cyberattacks focused on organizations, the fall campaign honed in on specific individuals: scholars in the field of political science, international relations, and global economics, working at major Russian universities and research institutions.\\n\\nThe emails received by the victims were sent from the address `support@e-library[.]wiki`. The campaign purported to be from the scientific electronic library, eLibrary, whose legitimate website is `elibrary.ru`. The phishing emails contained a malicious link in the format: `https:\/\/e-library[.]wiki\/elib\/wiki.php?id=\\u003c8 pseudorandom letters and digits\\u003e`. Recipients were prompted to click the link to download a plagiarism report. Clicking that link triggered the download of an archive file. The filename was personalized, using the victim&#8217;s own name in the format: `\\u003cLastName\\u003e_\\u003cFirstName\\u003e_\\u003cPatronymic\\u003e.zip`.\\n\\n## A well-prepared attack\\n\\nThe attackers did their homework before sending out the phishing emails. The malicious domain, `e-library[.]wiki`, was registered back in March 2025, over six months before the email campaign started. This was likely done to build the domain&#8217;s reputation, as sending emails from a suspicious, newly registered domain is a major red flag for spam filters.\\n\\nFurthermore, the attackers placed a copy of the legitimate eLibrary homepage on `https:\/\/e-library[.]wiki`. According to the information on the page, they accessed the legitimate website from the IP address `193.65.18[.]14` back in December 2024.\\n\\n![A screenshot of the malicious site elements showing the IP address and initial session date](https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2025\/12\/16201932\/operation-forumtroll1.png)\\n\\nA screenshot of the malicious site elements showing the IP address and initial session date\\n\\nThe attackers also carefully personalized the phishing emails for their targets, specific professionals in the field. As mentioned above, the downloaded archive was named with the victim&#8217;s last name, first name, and patronymic.\\n\\nAnother noteworthy technique was the attacker&#8217;s effort to hinder security analysis by restricting repeat downloads. When we attempted to download the archive from the malicious site, we received a message in Russian, indicating the download link was likely for one-time use only:\\n\\n![The message that was displayed when we attempted to download the archive](https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2025\/12\/16202012\/operation-forumtroll2.png)\\n\\nThe message that was displayed when we attempted to download the archive\\n\\nOur investigation found that the malicious site displayed a different message if the download was attempted from a non-Windows device. In that case, it prompted the user to try again from a Windows computer.\\n\\n![The message that was displayed when we attempted to download the archive from a non-Windows OS](https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2025\/12\/16202050\/operation-forumtroll3.png)\\n\\nThe message that was displayed when we attempted to download the archive from a non-Windows OS\\n\\n## The malicious archive\\n\\nThe malicious archives downloaded via the email links contained the following:\\n\\n  * A malicious shortcut file named after the victim: `\\u003cLastName\\u003e_\\u003cFirstName\\u003e_\\u003cPatronymic\\u003e.lnk`;\\n  * A `.Thumbs` directory containing approximately 100 image files with names in Russian. These images were not used during the infection process and were likely added to make the archives appear less suspicious to security solutions.\\n\\n\\n\\n![A portion of the .Thumbs directory contents](https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2025\/12\/16202133\/operation-forumtroll4.png)\\n\\nA portion of the .Thumbs directory contents\\n\\nWhen the user clicked the shortcut, it ran a PowerShell script. The script&#8217;s primary purpose was to download and execute a PowerShell-based payload from a malicious server.\\n\\n![The script that was launched by opening the shortcut](https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2025\/12\/16202210\/operation-forumtroll5.png)\\n\\nThe script that was launched by opening the shortcut\\n\\nThe downloaded payload then performed the following actions:\\n\\n  * Contacted a URL in the format: `https:\/\/e-library[.]wiki\/elib\/query.php?id=\\u003c8 pseudorandom letters and digits\\u003e\\u0026key=\\u003c32 hexadecimal characters\\u003e` to retrieve the final payload, a DLL file.\\n  * Saved the downloaded file to `%localappdata%\\\\Microsoft\\\\Windows\\\\Explorer\\\\iconcache_\\u003c4 pseudorandom digits\\u003e.dll`.\\n  * Established persistence for the payload using COM Hijacking. This involved writing the path to the DLL file into the registry key HKCR\\\\CLSID\\\\\\\\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\\\\InProcServer32. Notably, the attackers had used that same technique in their spring attacks.\\n  * Downloaded a decoy PDF from a URL in the format: `https:\/\/e-library[.]wiki\/pdf\/\\u003c8 pseudorandom letters and digits\\u003e.pdf`. This PDF was saved to the user&#8217;s Downloads folder with a filename in the format: `\\u003cLastName\\u003e_\\u003cFirstName\\u003e_\\u003cPatronymic\\u003e.pdf` and then opened automatically.\\n\\n\\n\\nThe decoy PDF contained no valuable information. It was merely a blurred report generated by a Russian plagiarism-checking system.\\n\\n![A screenshot of a page from the downloaded report](https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2025\/12\/16202308\/operation-forumtroll6.png)\\n\\nA screenshot of a page from the downloaded report\\n\\nAt the time of our investigation, the links for downloading the final payloads didn&#8217;t work. Attempting to access them returned error messages in English: \\&#8221;You are already blocked\u2026\\&#8221; or \\&#8221;You have been bad ended\\&#8221; (sic). This likely indicates the use of a protective mechanism to prevent payloads from being downloaded more than once. Despite this, we managed to obtain and analyze the final payload.\\n\\n## The final payload: the Tuoni framework\\n\\nThe DLL file deployed to infected devices proved to be an OLLVM-obfuscated loader, which we described in our previous report on Operation ForumTroll. However, while this loader previously delivered rare implants like LeetAgent and Dante, this time the attackers opted for a better-known commercial red teaming framework: Tuoni. Portions of the Tuoni code are publicly available on GitHub. By deploying this tool, the attackers gained remote access to the victim&#8217;s device along with other capabilities for further system compromise.\\n\\nAs in the previous campaign, the attackers used `fastly.net` as C2 servers.\\n\\n## Conclusion\\n\\nThe cyberattacks carried out by the ForumTroll APT group in the spring and fall of 2025 share significant similarities. In both campaigns, infection began with targeted phishing emails, and persistence for the malicious implants was achieved with the COM Hijacking technique. The same loader was used to deploy the implants both in the spring and the fall.\\n\\nDespite these similarities, the fall series of attacks cannot be considered as technically sophisticated as the spring campaign. In the spring, the ForumTroll APT group exploited zero-day vulnerabilities to infect systems. By contrast, the autumn attacks relied entirely on social engineering, counting on victims not only clicking the malicious link but also downloading the archive and launching the shortcut file. Furthermore, the malware used in the fall campaign, the Tuoni framework, is less rare.\\n\\nForumTroll has been targeting organizations and individuals in Russia and Belarus since at least 2022. Given this lengthy timeline, it is likely this APT group will continue to target entities and individuals of interest within these two countries. We believe that investigating ForumTroll&#8217;s potential future campaigns will allow us to shed light on shadowy malicious implants created by commercial developers \u2013 much as we did with the discovery of the Dante spyware.\\n\\n## Indicators of compromise\\n\\ne-library[.]wiki  \\nperf-service-clients2.global.ssl.fastly[.]net  \\nbus-pod-tenant.global.ssl.fastly[.]net  \\nstatus-portal-api.global.ssl.fastly[.]net&#8221;,&#8221;published&#8221;:&#8221;2025-12-17T10:00:51&#8243;,&#8221;modified&#8221;:&#8221;2025-12-17T10:00:51&#8243;,&#8221;type&#8221;:&#8221;securelist&#8221;,&#8221;title&#8221;:&#8221;Operation ForumTroll continues: Russian political scientists targeted using plagiarism reports&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;SECURELIST:E7FB3FBADAF7528523707FFB60591D8A&#8221;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-2783&#8243;],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:8.3,&#8221;severity&#8221;:&#8221;HIGH&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:C\/C:H\/I:H\/A:H&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/securelist.com\/operation-forumtroll-new-targeted-campaign\/118492\/&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-12-17T10:05:09&#8243;,&#8221;description&#8221;:&#8221;![](https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2025\/12\/17093749\/forumtroll-part-3-featured-image-990&#215;400.jpg)\\n\\n## Introduction\\n\\nIn March 2025, we discovered Operation ForumTroll, a series of sophisticated cyberattacks exploiting the CVE-2025-2783 vulnerability in Google Chrome. We previously detailed the malicious&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,99,12,15,13,136,7,11,5],"class_list":["post-31517","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-cvss-83","tag-exploit","tag-high","tag-news","tag-securelist","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Operation ForumTroll continues: Russian political scientists targeted using plagiarism reports_SECURELIST:E7FB3FBADAF7528523707FFB60591D8A - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=31517\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Operation ForumTroll continues: Russian political scientists targeted using plagiarism reports_SECURELIST:E7FB3FBADAF7528523707FFB60591D8A - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-12-17T10:05:09&#8243;,&#8221;description&#8221;:&#8221;![](https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2025\/12\/17093749\/forumtroll-part-3-featured-image-990&#215;400.jpg)nn## IntroductionnnIn March 2025, we discovered Operation ForumTroll, a series of sophisticated cyberattacks exploiting the CVE-2025-2783 vulnerability in Google Chrome. We previously detailed the malicious...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=31517\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-17T04:45:26+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31517#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31517\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Operation ForumTroll continues: Russian political scientists targeted using plagiarism reports_SECURELIST:E7FB3FBADAF7528523707FFB60591D8A\",\"datePublished\":\"2025-12-17T04:45:26+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31517\"},\"wordCount\":1519,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-8.3\",\"exploit\",\"HIGH\",\"news\",\"securelist\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=31517#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31517\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31517\",\"name\":\"Operation ForumTroll continues: Russian political scientists targeted using plagiarism reports_SECURELIST:E7FB3FBADAF7528523707FFB60591D8A - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-12-17T04:45:26+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31517#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=31517\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31517#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Operation ForumTroll continues: Russian political scientists targeted using plagiarism reports_SECURELIST:E7FB3FBADAF7528523707FFB60591D8A\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Operation ForumTroll continues: Russian political scientists targeted using plagiarism reports_SECURELIST:E7FB3FBADAF7528523707FFB60591D8A - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=31517","og_locale":"en_US","og_type":"article","og_title":"Operation ForumTroll continues: Russian political scientists targeted using plagiarism reports_SECURELIST:E7FB3FBADAF7528523707FFB60591D8A - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-12-17T10:05:09&#8243;,&#8221;description&#8221;:&#8221;![](https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2025\/12\/17093749\/forumtroll-part-3-featured-image-990&#215;400.jpg)nn## IntroductionnnIn March 2025, we discovered Operation ForumTroll, a series of sophisticated cyberattacks exploiting the CVE-2025-2783 vulnerability in Google Chrome. We previously detailed the malicious...","og_url":"https:\/\/zero.redgem.net\/?p=31517","og_site_name":"zero redgem","article_published_time":"2025-12-17T04:45:26+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=31517#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=31517"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Operation ForumTroll continues: Russian political scientists targeted using plagiarism reports_SECURELIST:E7FB3FBADAF7528523707FFB60591D8A","datePublished":"2025-12-17T04:45:26+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=31517"},"wordCount":1519,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-8.3","exploit","HIGH","news","securelist","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=31517#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=31517","url":"https:\/\/zero.redgem.net\/?p=31517","name":"Operation ForumTroll continues: Russian political scientists targeted using plagiarism reports_SECURELIST:E7FB3FBADAF7528523707FFB60591D8A - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-12-17T04:45:26+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=31517#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=31517"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=31517#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Operation ForumTroll continues: Russian political scientists targeted using plagiarism reports_SECURELIST:E7FB3FBADAF7528523707FFB60591D8A"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/31517","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=31517"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/31517\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=31517"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=31517"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=31517"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}