Trojanized ESET Installers Drop Kalambur Backdoor in Phishing Attacks on Ukraine

As part of phishing assaults against Ukrainian companies, a hitherto unidentified threat activity cluster has been seen posing as the Slovak cybersecurity firm ESET.

The security group, known as InedibleOchotense, tracks the campaign that was discovered in May 2025 and characterizes it as being aligned with Russia.

Unfit for consumptionAccording to ESET’s APT Activity Report Q2 2025–Q3 2025, which was provided with The Hacker News, Ochotense sent spear-phishing emails and Signal text messages to several Ukrainian companies that included a link to a trojanized ESET installer.

It is determined that InedibleOchotense shares tactical similarities with a campaign reported by CERT-UA as UAC-0212, which it defines as a sub-cluster inside the Sandworm (also known as APT44) hacking group, and EclecticIQ as involving the introduction of a backdoor dubbed BACKORDER read more about Trojanized ESET Installers Drop Kalambur Backdoor in Phishing Attacks on Ukraine.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *