Russia-aligned threat actor InedibleOchotense conducted a spear-phishing campaign targeting Ukrainian entities by impersonating the Slovak cybersecurity company ESET. Attackers distributed trojanized ESET installers via phishing emails and Signal messages, directing victims to fake ESET-branded domains such as esetsmart[.]com, esetscanner[.]com, and esetremover[.]com. The malicious installers delivered both a legitimate ESET AV Remover and the Kalambur backdoor, exploiting ESET’s strong reputation in Ukraine to increase the likelihood of successful compromise. The phishing messages contained minor language errors, likely due to poor translation from Russian to Ukrainian, and warned recipients of suspicious activity to prompt urgent action.
The Kalambur backdoor, also known as SUMBUR, is a C# malware that leverages the Tor network for command-and-control communications and can deploy additional tools such as OpenSSH and enable RDP access on port 3389. Security researchers noted tactical overlaps between this campaign and previous activity attributed to UAC-0212 and the BACKORDER downloader, with some reports linking related activity to Sandworm sub-clusters UAC-0125. The campaign was first detected in May 2025 and highlights ongoing Russian cyber operations targeting Ukraine through sophisticated social engineering and malware delivery techniques.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
In reporting on the campaign, ESET said the operation shared tactics with activity previously attributed to UAC-0212 and the BACKORDER downloader. Researchers also noted language mistakes in the lures that suggested poor translation from Russian to Ukrainian.
Victims who downloaded the fake installers received a legitimate ESET product together with the Kalambur backdoor, allowing the attackers to compromise targeted Ukrainian systems while appearing trustworthy.
In May 2025, the Russia-linked threat actor InedibleOchotense conducted a spearphishing campaign targeting Ukrainian entities. The attackers used phishing emails and Signal messages impersonating ESET to direct victims to fake domains hosting trojanized installers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.