A hacking group is impersonating Slovak cybersecurity company ESET in attacks phishing targeting Ukrainian entities and distributing the Kalambur backdoor.

The campaign, detected in May 2025, is being monitored by the security group under the alias InedibleOchotense and appears to be associated with Russia.
“ InedibleOchotense sent spear-phishing emails and text messages via Signal, containing a link to a modified ESET installer, to multiple Ukrainian entities ,” ESET reported in its “ APT Activity Report Q2 2025–Q3 2025. ”
It is believed that InedibleOchotense shares similarities with a campaign documented by EclecticIQ, which involved the deployment of a backdoor called BACKORDER. It also has similarities with a group tracked as UAC-0212 by CERT-UA, and described as a subgroup of Sandworm (also known as APT44).
See also: FIN7: Using Windows SSH Backdoor for remote access
New campaign misuses ESET name to distribute Kalambur backdoor
While the phishing email is written in Ukrainian, ESET said the first line uses a Russian word, likely indicating a typo or translation error. The email, purporting to come from ESET, claims that its monitoring team has detected a suspicious process associated with the victim's email address and that their computers may be at risk.

The activity is an attempt to exploit the widespread use of ESET software in the country and the brand's reputation. The goal is to trick recipients into installing malicious installers hosted on domains such as esetsmart[.]com, esetscanner[.]com, and esetremover[.]com.
See also: New HttpTroy backdoor disguises itself as a VPN invoice
The installer is designed to deliver the legitimate ESET AV Remover, along with a variant of a C# backdoor called Kalambur (also known as SUMBUR). It uses the Tor anonymity network for command and control. It is also capable of installing OpenSSH and enabling remote access via Remote Desktop Protocol (RDP) on port 3389.
It is worth noting that CERT-UA, in a report published last month, attributed a nearly identical campaign to UAC-0125, another Sandworm sub-cluster.
Sandworm, according to ESET, continued to execute destructive campaigns in Ukraine, launching two wiper malware tracked as ZEROLOT and Sting. They targeted an unnamed university in April 2025, followed by other data wiper attacks targeting government, energy, accounting, and agricultural organizations.
See also: PolarEdge: New custom backdoor TLS Server

“During this period, we observed and confirmed that the UAC-0099 group conducted initial access operations and then transferred validated targets to Sandworm for subsequent malicious activity,” the company said. “These devastating attacks from Sandworm are a reminder that data wipers are frequently used by Russian threat actors to target Ukraine.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
