Last seven days
- First activity
- Aug 7, 2026
- Last activity
- Aug 7, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
Dante is a commercial spyware/surveillance platform developed by the Italian company Memento Labs, formerly Hacking Team.
Profile source: Mallory opens in a new tabDante
Dante is a commercial spyware/surveillance platform developed by the Italian company Memento Labs, formerly Hacking Team. Kaspersky identified it in attacks linked to the ForumTroll cluster and traced related activity back to at least 2022, including operations targeting organizations and individuals in Russia and Belarus. Reported targets included media outlets, universities, research centers, government organizations, financial institutions, and individual scholars. Dante was not directly observed in the March 2025 Operation ForumTroll Chrome zero-day intrusion chain, but Kaspersky found it in related attacks and confirmed a direct link where LeetAgent was used to launch Dante.
The malware is described as a modular spyware implant with multiple surveillance and data-exfiltration functions, including keylogging, screenshot capture, file theft, and remote command execution. It uses an orchestrator/controller component to manage HTTPS command-and-control, module handling, self-protection, and self-removal. Dante loads encrypted plug-in modules from disk or memory; modules are stored locally and encrypted with AES-256/AES-encrypted data tied to device-unique information such as CPU identifier and Windows Product ID, and some reporting also notes host binding via machine-specific values. It can self-delete if it does not receive commands after a set time.
Dante employs extensive anti-analysis and evasion measures. Reported protections include VMProtect-based code obfuscation, encrypted strings, anti-debugging, anti-sandbox and virtual-machine detection, indirect Windows API calls to reduce detection, and disguising its orchestrator as a font file. Analysts also reported similarities with Hacking Team’s legacy RCS/Da Vinci spyware, including code overlap and lineage indicators. In related ForumTroll-linked operations, shared tradecraft included phishing-based delivery, use of Chrome zero-day CVE-2025-2783 in some campaigns, COM hijacking persistence, and overlaps in code, file-system paths, and data hidden in font files. High-confidence attribution in the content links Dante to Memento Labs based on malware naming artifacts, version references, and similarities to later Hacking Team RCS samples.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
While analyzing the malware used in these attacks, we discovered an unknown piece of malware that we identified as commercial spyware called “Dante” and developed by the Italian company Memento Labs (formerly Hacking Team).
Analyzing the old attacks, the researchers found "an unknown piece of malware that we identified as commercial spyware called “Dante” and developed by the Italian company Memento Labs."
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.