Skip to content
Breaking
Latest technical intelligence from Northeast India • Infrastructure, AI, Cloud & Security Analysis • Precision Analysis | Raw Intelligence | Your North Star of Tech Latest technical intelligence from Northeast India • Infrastructure, AI, Cloud & Security Analysis • Precision Analysis | Raw Intelligence | Your North Star of Tech
SECURITY

Analysis: New ForumTroll Phishing Attacks Target Russian Scholars Using Fake eLibrary Emails

Phishing Attacks Target Russian Scholars: A Cybersecurity Concern for North East India

Phishing Attacks Target Russian Scholars: A Cybersecurity Concern for North East India

A new wave of phishing attacks, linked to Operation ForumTroll, has been targeting Russian scholars, according to Kaspersky. These attacks, which began in October 2025, underscore the ongoing cybersecurity threats that could potentially impact the North East region of India and the broader Indian context.

Targeted Individuals and Institutions

The attacks, as revealed by security researcher Georgy Kucherin, are specifically targeting scholars in the field of political science, international relations, and global economics, working at major Russian universities and research institutions. This targeted approach, focusing on individuals rather than organizations, presents a more sophisticated threat vector.

Emails Masquerading as eLibrary

The phishing emails, appearing to be from eLibrary, a Russian scientific electronic library, are the initial point of contact. The emails are sent from the address "support@e-library[.]wiki," a domain registered six months before the start of the campaign, suggesting careful planning and preparation.

Tactics and Techniques Used

Strategic Domain Aging and Maintaining the Ruse

The attackers employed strategic domain aging, a tactic designed to avoid raising red flags typically associated with sending emails from a freshly registered domain. Additionally, they hosted a copy of the legitimate eLibrary homepage on the bogus domain to maintain the deception.

Ransomware and Other Malware

The emails lead to malicious sites that have been linked to ransomware attacks since May 2025. The attacks have been found to exploit security flaws in various software, including Microsoft SharePoint, Ivanti Endpoint Manager Mobile, Ivanti Connect Secure, and Ivanti Sentry.

Relevance to North East India and Broader Indian Context

While the attacks are currently targeted at Russian scholars, the tactics and techniques employed could potentially be adapted to target institutions and individuals in the North East region of India or the broader Indian context. Cybersecurity threats are a global concern, and understanding these threats can help local organizations and institutions better protect themselves.

Reflections and Future Implications

As cyber threats continue to evolve, it is crucial for organizations and individuals to remain vigilant and proactive in safeguarding their digital assets. Awareness and education about these threats can help mitigate potential risks. Furthermore, collaboration between cybersecurity organizations, both within India and globally, can help in identifying and responding to these threats more effectively.