Russia-Backed Hackers Target Ukraine with Fake ESET Installers: Inside the Kalambur Backdoor…
In the escalating Russia-Ukraine cyber war, a shadowy threat actor is weaponizing trusted antivirus software to infiltrate Ukrainian…
Russia-Backed Hackers Target Ukraine with Fake ESET Installers: Inside the Kalambur Backdoor Campaign

cyberwar
In the escalating Russia-Ukraine cyber war, a shadowy threat actor is weaponizing trusted antivirus software to infiltrate Ukrainian systems. Dubbed InedibleOchotense by ESET researchers, this Russia-aligned group has been caught distributing trojanized ESET installers laced with the Kalambur backdoor (also known as SUMBUR). First spotted in May 2025, the campaign exploits ESET’s massive popularity in Ukraine to deliver devastating payloads via phishing emails and Signal messages.
This isn’t just another hack — it’s a calculated strike in the ongoing cyber conflict between Russia and Ukraine, blending social engineering with advanced malware. As Sandworm APT (Russia’s notorious GRU-linked group) ramps up wiper attacks, InedibleOchotense adds espionage fuel to the fire. Here’s what you need to know to stay ahead in 2025’s volatile threat landscape
The Phishing Trap: How Fake ESET Tools Drop the Kalambur BackdoorThe attack starts with spear-phishing emails written in Ukrainian — but with a telling Russian slip-up in the opening line, hinting at the perpetrators’ origins.
Posing as ESET’s monitoring team, the messages warn of “suspicious processes” tied to the victim’s email, urging immediate action to “protect” their computer.Victims are directed to malicious domains like:
- esetsmart[.]com
- esetscanner[.]com
- esetremover[.]com
These sites host trojanized ESET AV Remover installers. On the surface, they run the legitimate tool to remove competing antivirus software. But in the background? They unleash Kalambur, a C# backdoor that:
- Connects to Tor for anonymous command-and-control (C2)
- Drops OpenSSH for persistent access
- Enables RDP on port 3389 for remote desktop takeover
ESET’s Q2–Q3 2025 APT Report links InedibleOchotense to overlaps with Sandworm’s BACKORDER campaign and CERT-UA’s UAC-0212 cluster. While similarities exist with UAC-0125 (another Sandworm sub-group), independent confirmation is pending. “It’s a weakly tied but tactically aligned effort,” says ESET senior malware researcher Matthieu Faou.
Pro Tip for SEO & Security Pros: Search trends for “Kalambur backdoor” and “trojanized ESET installer” are spiking amid Ukraine cyber alerts. Monitor these for real-time threat intel.
Ties to Sandworm: Wiper Malware Ravages Ukrainian SectorsInedibleOchotense doesn’t operate in a vacuum. Sandworm (APT44) — infamous for NotPetya and Ukrainian blackouts — continues its destructive spree:
- April 2025: Deployed ZEROLOT and Sting wipers against a Ukrainian university.
- Ongoing: Multiple wiper variants hit government, energy, logistics, and grain sectors.
ESET observed UAC-0099 handling initial access, then handing off to Sandworm for wipes. This “access broker” model amplifies Russia’s hybrid warfare, where destructive malware in Ukraine remains a go-to tool.
RomCom Joins the Fray: Exploiting WinRAR Zero-Day (CVE-2025–8088)Not to be outdone, RomCom (Storm-0978, UNC2596) — another Russia-aligned actor — launched mid-July 2025 spear-phishing using a WinRAR vulnerability (CVE-2025–8088, CVSS 8.8). Targets? European and Canadian firms in finance, manufacturing, defense, and logistics.Exploitation drops:
- SnipBot (RomCom RAT 5.0 variant)
- RustyClaw
- Mythic agent
Originally an e-crime ransomware enabler, RomCom has pivoted to nation-state ops, tracking Ukraine war geopolitics for credential theft and exfiltration.
AttackIQ’s September 2025 profile calls it a “utility for Russian objectives.”Why This Matters in 2025’s Cyber Threat LandscapeAs Russia-Ukraine conflict Google Trends surge (tied to recent escalations), these campaigns highlight:
- Brand impersonation risks: ESET’s 70%+ market share in Ukraine makes it prime bait.
- Supply chain attacks: Trojanized legit tools evade detection.
- Tor & RDP persistence: Hard-to-trace backdoors for long-term espionage.

Defend Against Trojanized Installers and Backdoors: Actionable Steps
- Verify sources: Download ESET tools only from official sites.
- Enable MFA & monitor RDP: Block port 3389 externally; use VPNs.
- Patch WinRAR immediately: CVE-2025–8088 is actively exploited.
- Hunt for IOCs: Scan for Tor traffic, OpenSSH drops, or Kalambur artifacts.
- Employee training: Flag Ukrainian-language phishing with Russian errors.
In a world where cyber espionage and destructive attacks blur lines, vigilance is your best defense. Russia-backed groups like Sandworm and RomCom aren’t slowing down — neither should your security posture.Stay safe out there. Follow for more on APT44 Sandworm, Russia cyber attacks, and emerging threats.
Source: https://thehackernews.com/2025/11/trojanized-eset-installers-drop.html
메타데이터
- post_id
- 97d2d1e6b221
- slug
- russia-backed-hackers-target-ukraine-with-fake-eset-installers-inside-the-kalambur-backdoor-97d2d1e6b221
- url
- https://medium.com/@costigermano/russia-backed-hackers-target-ukraine-with-fake-eset-installers-inside-the-kalambur-backdoor-97d2d1e6b221
- canonical_url
- https://medium.com/@costigermano/russia-backed-hackers-target-ukraine-with-fake-eset-installers-inside-the-kalambur-backdoor-97d2d1e6b221
- author_url
- https://medium.com/@costigermano
- status
- ok
- fetched_at
- 2026-07-20 16:03:09