Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
CEO of surveillance software company Memento Labs admits that one of its governmental clients was discovered deploying its malware

CEO of surveillance software company Memento Labs admits that one of its governmental clients was discovered deploying its malware

Bitget-RWA2025/10/29 11:36
By:Bitget-RWA

On Monday, cybersecurity firm Kaspersky released findings on a newly discovered spyware named Dante, which reportedly targeted Windows systems in Russia and neighboring Belarus. According to the researchers, Dante was developed by Memento Labs, a surveillance technology company based in Milan that emerged in 2019 after acquiring the assets of the earlier spyware developer Hacking Team.

Paolo Lezzi, CEO of Memento, confirmed to TechCrunch that the spyware identified by Kaspersky is indeed a product of Memento.

During a phone conversation, Lezzi attributed the exposure of Dante to one of their government clients, stating that the client had deployed an outdated version of the Windows spyware, which Memento plans to discontinue support for by year’s end.

“They were clearly using an agent that was already obsolete,” Lezzi explained to TechCrunch, using “agent” as the technical term for the spyware installed on a victim’s device.

“I actually thought [the government client] had stopped using it,” Lezzi remarked.

Lezzi, who mentioned he was unsure which specific clients were involved, also noted that Memento had already instructed all its clients to cease using the Windows malware. He said the company had warned its customers since December 2024 that Kaspersky had detected Dante infections. Memento intends to remind all clients again on Wednesday to discontinue use of the Windows spyware.

He further stated that Memento now focuses solely on developing spyware for mobile devices. The company also works with zero-day vulnerabilities—security flaws unknown to software vendors that can be exploited to install spyware—though Lezzi said most of these exploits are sourced from external developers.

When contacted by TechCrunch, Kaspersky spokesperson Mai Al Akka declined to specify which government might be behind the spying operation, only stating that it was “an entity capable of utilizing Dante software.”

“This group is notable for its strong command of Russian and familiarity with local context, which Kaspersky has seen in other [state-sponsored] operations. However, occasional mistakes indicate the attackers are not native speakers,” Al Akka told TechCrunch.

Kaspersky’s latest report describes a hacking group it calls “ForumTroll” using Dante spyware to target individuals invited to the Primakov Readings, a Russian political and economic forum. The hackers reportedly attacked a wide array of sectors in Russia, including media, academia, and government agencies.

Kaspersky discovered Dante after detecting a surge of cyberattacks using phishing links that exploited a Chrome browser zero-day vulnerability. Lezzi clarified that Memento was not responsible for developing the Chrome zero-day exploit.

Kaspersky’s report notes that Memento continued to enhance the spyware originally created by Hacking Team until 2022, at which point Dante replaced it.

Lezzi acknowledged that certain features or behaviors in Memento’s Windows spyware may have been inherited from Hacking Team’s earlier products.

A key indicator that the spyware identified by Kaspersky was linked to Memento was the presence of the term “DANTEMARKER” in its code—a direct nod to the Dante name, which Memento had previously revealed at a surveillance technology event, according to Kaspersky.

Similar to Dante, some versions of Hacking Team’s spyware, known as Remote Control System, were named after notable Italian historical figures like Leonardo Da Vinci and Galileo Galilei.

A history of hacks

In 2019, Lezzi acquired Hacking Team and rebranded it as Memento Labs. He told reporters that he paid just one euro for the company, with the intention of starting anew.

“We intend to overhaul everything,” Lezzi told Motherboard after the acquisition in 2019. “We’re beginning from the ground up.”

A year later, Hacking Team’s founder and CEO David Vincenzetti declared the company “dead.”

After acquiring Hacking Team, Lezzi told TechCrunch that only three government clients remained, a significant drop from the more than 40 government customers the company had in 2015. That same year, hacktivist Phineas Fisher breached the company’s servers, stealing around 400 gigabytes of internal emails, contracts, documents, and spyware source code.

Prior to the breach, Hacking Team’s spyware had been used by clients in Ethiopia, Morocco, and the United Arab Emirates to target journalists, critics, and dissidents. Following the leak of internal data by Phineas Fisher, journalists uncovered that a regional government in Mexico used the spyware against local politicians, and that Hacking Team had sold its tools to countries with poor human rights records, such as Bangladesh, Saudi Arabia, and Sudan, among others.

Lezzi declined to disclose the current number of Memento’s clients to TechCrunch, but suggested it is fewer than 100. He also mentioned that only two former Hacking Team employees remain at Memento.

John Scott-Railton, a senior researcher at the University of Toronto’s Citizen Lab who has spent a decade studying spyware misuse, said the emergence of Memento’s spyware demonstrates the ongoing spread of surveillance technology. He added

It also illustrates that even after a company collapses due to a major hack and multiple scandals, a new firm with fresh spyware can still rise from its remains,

“This shows us the importance of maintaining accountability,” Scott-Railton told TechCrunch. “It’s telling that the legacy of such a notorious, compromised, and breached brand continues to persist.”

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

BNB News Update: Shattering Financial Limits: Ondo’s BNB Chain Growth Grants Global Investors Access to U.S. Markets

- Ondo Finance expands tokenized securities platform to BNB Chain, enabling non-U.S. investors to access 100+ U.S. stocks/ETFs via blockchain. - Partnership with Bitget Wallet and PancakeSwap offers zero-fee trading for 30 days, with assets backed by real-world securities and U.S. custodians. - Platform now supports Ethereum, Solana, and BNB Chain, achieving $1.8B TVL and targeting underserved Asian/Latin American markets for U.S. equity access. - BNB Chain's RWA ecosystem growth accelerates as Ondo become

Bitget-RWA2025/10/30 01:04
BNB News Update: Shattering Financial Limits: Ondo’s BNB Chain Growth Grants Global Investors Access to U.S. Markets

Privacy-Oriented Canton Seeks to Connect Wall Street and Blockchain Through $500M SPAC

- Canton Network plans $500M SPAC to invest in Canton Coin, a privacy-focused blockchain token. - DRW and Liberty City will fund with Canton Coins, while BitGo's custody services and institutional backing (Goldman Sachs, Tradeweb) drive adoption. - SPAC leadership (ex-DRW COO, Liberty City executive) aims to institutionalize the ecosystem through validator roles and applications. - Success depends on regulatory approval, market confidence, and uncertain public listing timelines amid crypto volatility risks.

Bitget-RWA2025/10/30 01:04
Privacy-Oriented Canton Seeks to Connect Wall Street and Blockchain Through $500M SPAC

Bitcoin Updates: Will Bitcoin Maintain $112K? Experts Watch for $120K Surge Before Fed Decision

- Bitcoin dips below $112,000 but analysts view it as key support ahead of Fed's policy decision, with potential rebound to $120,000. - U.S.-China trade progress and institutional demand boost crypto markets to $3.83 trillion, with Ethereum reclaiming $4,000. - Solana's ETF approval and Visa's stablecoin expansion highlight growing institutional confidence in crypto assets. - Market remains cautious as Bitcoin's open interest declines, but 60% of Binance traders expect upward movement post-FOMC.

Bitget-RWA2025/10/30 00:50
Bitcoin Updates: Will Bitcoin Maintain $112K? Experts Watch for $120K Surge Before Fed Decision

BNB News Update: Ondo’s Blockchain Bridge Opens Up U.S. Stock Market to International Investors

- Ondo Finance expands tokenized securities platform to BNB Chain, partnering with Bitget Wallet to offer U.S. stocks and ETFs to global users. - The platform targets 3.4 million daily active users in Asia and Latin America, enabling 24/5 trading with $1 minimums via blockchain infrastructure. - Competing with platforms like Backed and Kraken's xStocks, Ondo's tokens are transferable across Ethereum, Solana, and BNB Chain, enhancing liquidity. - Strategic partnerships and acquisitions, including $30M in fu

Bitget-RWA2025/10/30 00:50
BNB News Update: Ondo’s Blockchain Bridge Opens Up U.S. Stock Market to International Investors