Get all your news in one place.
100’s of premium titles.
One app.
Start reading
International Business Times
International Business Times

Kaspersky Discovers Dante Spyware Made by Memento Labs Targeting Russia, Belarus

Kaspersky has uncovered a sophisticated spyware operation titled Dante, said to be targeting Windows users in Russia and Belarus. It was also found out that the Italian surveillance technology firm Memento Labs created Dante in 2019 after it bought the notorious spyware vendor Hacking Team.

Kaspersky's analysis reveals that this sophisticated spyware compromised several sectors, such as media, educational institutions, and government organizations. The ForumTroll group used the bait of false invitations for a well-known Russian political and economic conference, Primakov Readings.

Memento Labs Affirms Spyware's Origin But Faults Clients

Russian government entities are observed to be vulnerable to cyberthreats. Kaspersky says that the "CloudSorcerer" APT group is the latest to hit the departments.

In an interview with TechCrunch, Memento Labs CEO Paolo Lezzi confirmed that Dante was owned by his company but faulted one of their government clients for the leak. He said that the spyware detected by Kaspersky was an old version that Memento had advised clients to abandon.

"Clearly, they used an agent that was already dead. I thought [the government customer] didn't even use it anymore."

Trail of Digital Espionage and a Notorious Legacy

Memento Labs' checkered past can be traced to Hacking Team, a spyware company notorious for trading in espionage tools to governments with alleged human rights records.

In 2015, the firm experienced a catastrophic data leak by hacktivist Phineas Fisher, which unveiled internal emails, contracts, and source code showing that its clients included Ethiopia, Morocco, and Saudi Arabia.

Following the hack, Hacking Team fell apart under international pressure. Lezzi purchased the business for a token euro, renaming it Memento Labs with a vow to restore its image. But recent developments indicate that remnants of the original spyware, such as Dante, continue to exist, years after restructuring.

Kaspersky's Findings Uncover Old Ghosts in New Code

Kaspersky researchers also found that the spyware had the code marker "DANTEMARKER," directly connecting it with Memento Labs. In their report, they concluded that Memento developed and refined the Hacking Team's inherited spyware until 2022, when Dante officially took over.

Kaspersky did not name the government behind the campaign but indicated that the attackers showed proficiency in fluent Russian and profound regional understanding, which indicates a local connection.

The Cycle of Surveillance Technology Continues

Experts say that the discovery of Dante confirms the relentless development of commercial spyware. Citizen Lab's John Scott-Railton said that even after previous scandals, there are still companies like Memento Labs thriving in new incarnations and with new tools.

Originally published on Tech Times

Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.