Memento Labs CEO Admits Government Client Misused Spyware in Major Cyber-Espionage Campaign

The CEO of *Memento Labs*, an Italian spyware manufacturer, has publicly confirmed that one of its government clients was caught using its spyware in a recent cyber-espionage campaign—a rare and revealing admission in the clandestine world of commercial surveillance technology. This incident provides a window into the shadowy intersection of state surveillance, commercial hacking tools, and the persistent risks of abuse and exposure.

## Memento Labs: The Shadowy Successor

Memento Labs, formerly known as Hacking Team, has long been a controversial figure in the global cyber-surveillance landscape. The company, based in Italy, gained notoriety in the early 2000s for selling advanced spyware to governments and law enforcement agencies around the world. After a damaging data breach and public backlash in 2015, Hacking Team was acquired and rebranded as Memento Labs in 2019[1][5].

Despite years of relative quiet, Memento Labs returned to the spotlight in 2025 when cybersecurity firm Kaspersky uncovered evidence of a new campaign—*Operation ForumTroll*—that deployed a sophisticated commercial spyware tool dubbed **Dante**[1][5][9]. Kaspersky researchers linked the malware campaign directly to Memento Labs, confirming the company’s continued activity in the global spyware market[1].

## The ForumTroll Campaign and the Dante Spyware

The malware campaign identified by Kaspersky targeted a range of organizations, including government agencies, media outlets, financial institutions, universities, and research centers, predominantly in Russia and Belarus[1][5][7].

Key details of the attack include:

– **Infection Vector:** Victims received personalized phishing emails disguised as invitations to the Primakov Readings, an international forum on politics and economics[1][9].
– **Zero-Click Exploitation:** Simply clicking the malicious link was sufficient to trigger infection; no further action was required. The malware exploited vulnerabilities in Google Chrome and other Chromium-based browsers to silently compromise targets[1][7].
– **Espionage Objectives:** The campaign exhibited hallmarks of an advanced persistent threat (APT), commonly associated with state-sponsored actors seeking long-term access to sensitive information[1][9].

The Dante spyware enabled attackers to escape browser sandboxes, steal files, monitor user activity, and potentially gain deep access to infected systems[7].

## CEO Confirms Government Customer Implicated

In a highly unusual move for the industry, the CEO of Memento Labs has confirmed that one of the company’s government clients was indeed caught using its spyware in the course of the ForumTroll campaign. While the CEO did not disclose the identity of the client, the admission aligns with public reporting that the campaign targeted Russian and Belarusian interests[1][5][9].

This level of confirmation is rare among spyware vendors, who typically maintain plausible deniability or claim to have little visibility into how clients use their products. The CEO’s statement underscores the company’s awareness of its customers’ activities and may reflect mounting pressure for transparency in an industry frequently criticized for enabling human rights abuses and political repression.

## The Broader Context: Commercial Spyware and Accountability

The exposure of Memento Labs’ spyware campaign and the CEO’s admission raise significant questions about the regulation and oversight of commercial surveillance tools:

– **Lack of Transparency:** Commercial spyware vendors operate in legal and ethical gray zones, often selling to governments with poor human rights records[1].
– **Risks of Abuse:** Tools like Dante provide powerful surveillance capabilities that can be misused for political repression, targeting journalists, activists, and dissidents.
– **International Scrutiny:** The European Union and other international bodies have called for stricter controls on the export and use of such technologies, citing repeated abuses.

The ForumTroll incident demonstrates how even sophisticated, well-resourced government customers are not immune to exposure when their operations are detected by leading cybersecurity firms. The technical details revealed by Kaspersky, including the use of zero-day browser exploits and highly targeted phishing, highlight both the sophistication of these attacks and the persistent arms race between offensive and defensive cyber capabilities[1][7][9].

## Industry Reactions and Future Implications

The revelation has sent ripples through the cybersecurity and human rights communities. Advocacy groups have seized on the incident as further evidence that commercial spyware is too dangerous to be left unregulated, while cybersecurity experts caution that similar campaigns are likely ongoing, often undetected[8][13].

For Memento Labs, the incident underscores the reputational risks of operating in a secretive and controversial sector. For governments and organizations worldwide, it serves as a stark reminder of the evolving threat landscape and the need for continual vigilance against targeted espionage campaigns.

As regulators, security professionals, and civil society debate the future of commercial spyware, the story of Memento Labs and its government customers offers a timely and sobering case study in the consequences of unchecked surveillance technology. The rare confirmation from the company’s CEO may mark a turning point in the industry’s approach to transparency—and the global conversation about the ethics of digital surveillance.


Original source: TechCrunch – CEO of spyware maker Memento Labs confirms one of its government customers was caught using its malware