On Monday, researchers at cybersecurity big Kaspersky printed a report figuring out a brand new spy ware known as Dante that they are saying focused Home windows victims in Russia and neighboring Belarus. The researchers mentioned the Dante spy ware is made by Memento Labs, a Milan-based surveillance tech maker that was shaped in 2019 after a brand new proprietor acquired and took over early spy ware maker Hacking Group.
Memento chief govt Paolo Lezzi confirmed to TechCrunch that the spy ware caught by Kaspersky does certainly belong to Memento.
In a name, Lezzi blamed one of many firm’s authorities clients for exposing Dante, saying the shopper used an outdated model of the Home windows spy ware that may not be supported by Memento by the top of this 12 months.
“Clearly they used an agent that was already lifeless,” Lezzi informed TechCrunch, referring to an “agent” because the technical phrase for the spy ware planted on the goal’s pc.
“I believed [the government customer] didn’t even use it anymore,” mentioned Lezzi.
Lezzi, who mentioned he was undecided which of the corporate’s clients have been caught, added that Memento had already requested that every one of its clients cease utilizing the Home windows malware. Lezzi mentioned the corporate had warned clients that Kaspersky had detected Dante spy ware infections since December 2024. He added that Memento plans to ship a message to all its clients on Wednesday asking them as soon as once more to cease utilizing its Home windows spy ware.
He additionally mentioned that Memento at present solely develops spy ware for cellular platforms. The corporate additionally develops some zero-days — which means safety flaws in software program unknown to the seller that can be utilized to ship spy ware — although, the corporate principally sources its exploits from exterior builders, in keeping with Lezzi.
Contact Us
Do you might have extra details about Memento Labs? Or different spy ware makers? From a non-work system, you may contact Lorenzo Franceschi-Bicchierai securely on Sign at +1 917 257 1382, or by way of Telegram, Keybase and Wire @lorenzofb, or by e-mail.
When reached by TechCrunch, Kaspersky spokesperson Mai Al Akka wouldn’t say which authorities Kaspersky believes is behind the espionage marketing campaign, however that it was “somebody who has been ready to make use of Dante software program.”
“The group stands out for its sturdy command of Russian and data of native nuances, traits that Kaspersky noticed in different campaigns linked to this [government-backed] risk. Nonetheless, occasional errors recommend that the attackers weren’t native audio system,” Al Akka informed TechCrunch.
In its new report, Kaspersky mentioned it discovered a hacking group utilizing the Dante spy ware that it refers to as “ForumTroll,” describing the focusing on of individuals with invitations to Russian politics and economics discussion board Primakov Readings. Kaspersky mentioned the hackers focused a broad vary of industries in Russia, together with media retailers, universities, and authorities organizations.
Kaspersky’s discovery of Dante got here after the Russian cybersecurity agency mentioned it detected a “wave” of cyberattacks with phishing hyperlinks that have been exploiting a zero-day within the Chrome browser. Lezzi mentioned that the Chrome zero-day was not developed by Memento.
In its report, Kaspersky researchers concluded that Memento “stored bettering” the spy ware initially developed by Hacking Group till 2022, when the spy ware was “changed by Dante.”
Lezzi conceded that it’s attainable that some “features” or “behaviors” of Memento’s Home windows spy ware have been left over from spy ware developed by Hacking Group.
A telltale signal that the spy ware caught by Kaspersky belonged to Memento was that the builders allegedly left the phrase “DANTEMARKER” within the spy ware’s code, a transparent reference to the title Dante, which Memento had beforehand and publicly disclosed at a surveillance tech convention, per Kaspersky.
Very similar to Memento’s Dante spy ware, some variations of Hacking Group’s spy ware, codenamed Distant Management System, have been named after historic Italian figures, corresponding to Leonardo Da Vinci and Galileo Galilei.
A historical past of hacks
In 2019, Lezzi bought Hacking Group and rebranded it to Memento Labs. Based on Lezzi, he paid just one euro for the corporate and the plan was to begin over.
“We wish to change completely all the things,” the Memento proprietor informed Motherboard after the acquisition in 2019. “We’re ranging from scratch.”
A 12 months later, Hacking Group’s CEO and founder David Vincenzetti introduced that Hacking Group was “lifeless.”
When he acquired Hacking Group, Lezzi informed TechCrunch that the corporate solely had three authorities clients remaining, a far cry from the greater than 40 authorities clients that Hacking Group had in 2015. That very same 12 months, a hacktivist known as Phineas Fisher broke into the startup’s servers and siphoned off some 400 gigabytes of inside emails, contracts, paperwork, and the supply code for its spy ware.
Earlier than the hack, Hacking Group’s clients in Ethiopia, Morocco, and the United Arab Emirates have been caught focusing on journalists, critics, and dissidents utilizing the corporate’s spy ware. As soon as Phineas Fisher printed the corporate’s inside information on-line, journalists revealed {that a} Mexican regional authorities used Hacking Group’s spy ware to focus on native politicians, and that Hacking Group had bought to international locations with human rights abuses, together with Bangladesh, Saudi Arabia, and Sudan, amongst others.
Lezzi declined to inform TechCrunch what number of clients Memento at present has, however implied it was fewer than 100 clients. He additionally mentioned that there are solely two present Memento staff left from Hacking Group’s former employees.
The invention of Memento’s spy ware reveals that this kind of surveillance expertise retains proliferating, in keeping with John Scott-Railton, a senior researcher who has investigated spy ware abuses for a decade on the College of Toronto’s Citizen Lab. It additionally reveals
Additionally {that a} controversial firm can die due to a spectacular hack and several other scandals, and but a brand new firm with model new spy ware can nonetheless come out of its ashes,
“It tells us that we have to sustain the concern of penalties,” Scott-Railton informed TechCrunch. “It says loads that echoes of probably the most radioactive, embarrassed and hacked model are nonetheless round.”