Home » Trojanized ESET Installers Drop Kalambur Backdoor in Phishing Attacks on Ukraine

Trojanized ESET Installers Drop Kalambur Backdoor in Phishing Attacks on Ukraine

by
2 minutes read

In a recent cybersecurity development, a concerning trend has emerged with threat actors disguising themselves as reputable entities to carry out malicious activities. One such instance involves a cluster of threat actors impersonating the well-known Slovak cybersecurity company ESET in phishing attacks aimed at Ukrainian organizations.

This devious campaign, identified in May 2025, has been attributed to a group known as InedibleOchotense, believed to have ties to Russia. Their modus operandi involves sending spear-phishing emails and Signal text messages to unsuspecting targets, enticing them to click on a link that leads to a Trojanized ESET installer.

Upon clicking the link, victims unknowingly download a backdoor known as Kalambur, allowing threat actors to gain unauthorized access to sensitive systems and data. This sophisticated tactic not only compromises the security of the targeted organizations but also underscores the evolving nature of cyber threats in today’s digital landscape.

The use of legitimate software installers as a vehicle for malware delivery is particularly insidious, as it leverages the trust associated with reputable brands like ESET to deceive users. This type of social engineering highlights the importance of remaining vigilant and verifying the authenticity of sources, even when seemingly reputable names are involved.

For IT and development professionals, this incident serves as a stark reminder of the ever-present risks posed by cyber threats and the need for robust security measures. Implementing multi-layered defenses, conducting regular security training for employees, and staying informed about emerging threats are crucial steps in safeguarding against such malicious activities.

As the cybersecurity landscape continues to evolve, threat actors will likely explore new techniques to bypass defenses and exploit vulnerabilities. By staying proactive and informed, organizations can better protect themselves against sophisticated attacks like the one orchestrated by the InedibleOchotense group.

In conclusion, the emergence of Trojanized ESET installers dropping the Kalambur backdoor in phishing attacks on Ukraine underscores the importance of heightened cybersecurity awareness and diligence. By remaining vigilant, implementing best practices, and leveraging advanced security solutions, organizations can mitigate the risks posed by evolving cyber threats and safeguard their valuable assets from malicious actors.

You may also like