Wednesday, October 29, 2025

CEO of spy ware maker Memento Labs confirms certainly one of its authorities prospects was caught utilizing its malware


On Monday, researchers at cybersecurity big Kaspersky revealed a report figuring out a brand new spy ware referred to as Dante that they are saying focused Home windows victims in Russia and neighboring Belarus. The researchers mentioned the Dante spy ware is made by Memento Labs, a Milan-based surveillance tech maker that was fashioned in 2019 after a brand new proprietor acquired and took over early spy ware maker Hacking Crew.

Memento chief govt Paolo Lezzi confirmed to TechCrunch that the spy ware caught by Kaspersky does certainly belong to Memento.

In a name, Lezzi blamed one of many firm’s authorities prospects for exposing Dante, saying the client used an outdated model of the Home windows spy ware that may now not be supported by Memento by the top of this yr. 

“Clearly they used an agent that was already lifeless,” Lezzi advised TechCrunch, referring to an “agent” because the technical phrase for the spy ware planted on the goal’s laptop.

“I believed [the government customer] didn’t even use it anymore,” mentioned Lezzi. 

Lezzi, who mentioned he was undecided which of the corporate’s prospects had been caught, added that Memento had already requested that each one of its prospects cease utilizing the Home windows malware. Lezzi mentioned the corporate had warned prospects that Kaspersky had detected Dante spy ware infections since December 2024. He added that Memento plans to ship a message to all its prospects on Wednesday asking them as soon as once more to cease utilizing its Home windows spy ware.

He additionally mentioned that Memento presently solely develops spy ware for cellular platforms. The corporate additionally develops some zero-days — which means safety flaws in software program unknown to the seller that can be utilized to ship spy ware — although, the corporate principally sources its exploits from exterior builders, based on Lezzi. 

Contact Us

Do you’ve gotten extra details about Memento Labs? Or different spy ware makers? From a non-work system, you may contact Lorenzo Franceschi-Bicchierai securely on Sign at +1 917 257 1382, or through Telegram, Keybase and Wire @lorenzofb, or by e mail.

When reached by TechCrunch, Kaspersky spokesperson Mai Al Akka wouldn’t say which authorities Kaspersky believes is behind the espionage marketing campaign, however that it was “somebody who has been ready to make use of Dante software program.”

“The group stands out for its sturdy command of Russian and data of native nuances, traits that Kaspersky noticed in different campaigns linked to this [government-backed] risk. Nevertheless, occasional errors recommend that the attackers weren’t native audio system,” Al Akka advised TechCrunch.

In its new report, Kaspersky mentioned it discovered a hacking group utilizing the Dante spy ware that it refers to as “ForumTroll,” describing the focusing on of individuals with invitations to Russian politics and economics discussion board Primakov Readings. Kaspersky mentioned the hackers focused a broad vary of industries in Russia, together with media retailers, universities, and authorities organizations. 

Kaspersky’s discovery of Dante got here after the Russian cybersecurity agency mentioned it detected a “wave” of cyberattacks with phishing hyperlinks that had been exploiting a zero-day within the Chrome browser. Lezzi mentioned that the Chrome zero-day was not developed by Memento. 

In its report, Kaspersky researchers concluded that Memento “stored enhancing” the spy ware initially developed by Hacking Crew till 2022, when the spy ware was “changed by Dante.” 

Lezzi conceded that it’s attainable that some “points” or “behaviors” of Memento’s Home windows spy ware had been left over from spy ware developed by Hacking Crew.

A telltale signal that the spy ware caught by Kaspersky belonged to Memento was that the builders allegedly left the phrase “DANTEMARKER” within the spy ware’s code, a transparent reference to the identify Dante, which Memento had beforehand and publicly disclosed at a surveillance tech convention, per Kaspersky. 

Very like Memento’s Dante spy ware, some variations of Hacking Crew’s spy ware, codenamed Distant Management System, had been named after historic Italian figures, corresponding to Leonardo Da Vinci and Galileo Galilei.

A historical past of hacks

In 2019, Lezzi bought Hacking Crew and rebranded it to Memento Labs. In response to Lezzi, he paid just one euro for the corporate and the plan was to start out over. 

“We need to change completely every part,” the Memento proprietor advised Motherboard after the acquisition in 2019. “We’re ranging from scratch.”

A yr later, Hacking Crew’s CEO and founder David Vincenzetti introduced that Hacking Crew was “lifeless.”

When he acquired Hacking Crew, Lezzi advised TechCrunch that the corporate solely had three authorities prospects remaining, a far cry from the greater than 40 authorities prospects that Hacking Crew had in 2015. That very same yr, a hacktivist referred to as Phineas Fisher broke into the startup’s servers and siphoned off some 400 gigabytes of inner emails, contracts, paperwork, and the supply code for its spy ware.

Earlier than the hack, Hacking Crew’s prospects in Ethiopia, Morocco, and the United Arab Emirates had been caught focusing on journalists, critics, and dissidents utilizing the corporate’s spy ware. As soon as Phineas Fisher revealed the corporate’s inner knowledge on-line, journalists revealed {that a} Mexican regional authorities used Hacking Crew’s spy ware to focus on native politicians, and that Hacking Crew had offered to international locations with human rights abuses, together with Bangladesh, Saudi Arabia, and Sudan, amongst others.

Lezzi declined to inform TechCrunch what number of prospects Memento presently has, however implied it was fewer than 100 prospects. He additionally mentioned that there are solely two present Memento staff left from Hacking Crew’s former workers.

The invention of Memento’s spy ware reveals that this sort of surveillance expertise retains proliferating, based on John Scott-Railton, a senior researcher who has investigated spy ware abuses for a decade on the College of Toronto’s Citizen Lab. It additionally reveals

Additionally {that a} controversial firm can die due to a spectacular hack and several other scandals, and but a brand new firm with model new spy ware can nonetheless come out of its ashes, 

“It tells us that we have to sustain the concern of penalties,” Scott-Railton advised TechCrunch. “It says rather a lot that echoes of essentially the most radioactive, embarrassed and hacked model are nonetheless round.”

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles