BACKORDER is a downloader malware family referenced in reporting on Russia-linked activity targeting Ukrainian entities. ESET stated that a May 2025 spearphishing campaign conducted by the Russia-linked threat actor InedibleOchotense shared tactics with activity previously attributed to UAC-0212 and the BACKORDER downloader. Separate reporting also associates BackOrder with Sandworm, describing it alongside destructive malware used in operations aligned with Russian geopolitical objectives. The broader activity targeted Ukrainian entities and relied on social engineering, including phishing emails and Signal messages impersonating ESET, with trojanized installers hosted on fake domains such as esetsmart[.]com, esetscanner[.]com, and esetremover[.]com. High-confidence details in the provided content do not describe BACKORDER’s internal functionality beyond identifying it as a downloader, and no direct BACKORDER-specific IOCs are provided.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaign shares tactics with activity previously attributed to UAC-0212 and the BACKORDER downloader.
1 distinct technique documented for this family, organized by ATT&CK tactic.
Another Russia-aligned threat actor, InedibleOchotense, conducted a spearphishing campaign impersonating ESET. This campaign involved emails and Signal messages delivering a trojanized ESET installer... The Russia-aligned group sent phishing emails and Signal messages containing links to trojanized ESET installers hosted on fake domains.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A downloader previously associated with similar tactics referenced for comparison to this campaign.
Malware used by Sandworm for cyber espionage campaigns, targeting Ukrainian users and critical infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.