BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Russia-Aligned Hackers Use Fake ESET to Target Ukraine Entities

Russia-aligned threat groups InedibleOchotense and RomCom conduct spear-phishing attacks targeting Ukrainian and Western organizations with advanced backdoors and exploit zero-day vulnerabilities since mid-2025.

  • A Russia-aligned threat group called InedibleOchotense has launched phishing attacks impersonating Cybersecurity firm ESET targeting Ukrainian organizations since May 2025.
  • The attacks use spear-phishing emails and messages with links to a trojanized ESET installer designed to install a C# backdoor named Kalambur, which employs the Tor network for command-and-control.
  • The threat is linked to the Sandworm Hacking group, known for destructive wiper Malware attacks in Ukraine across various sectors including government and energy.
  • The RomCom group exploited a critical WinRAR vulnerability in July 2025 in spear-phishing campaigns targeting European and Canadian companies, deploying multiple backdoors.

Since May 2025, a previously unknown Russia-aligned cyber threat cluster named InedibleOchotense has conducted spear-phishing attacks targeting Ukrainian organizations. The group impersonated ESET, a Slovak cybersecurity firm, by sending emails and Signal text messages with links to malicious installers mimicking ESET software, as stated in ESET’s APT Activity Report Q2 2025–Q3 2025.

- Advertisement -

These fake installers delivered the authentic ESET AV Remover tool alongside a C# backdoor known as Kalambur or SUMBUR, which leverages the Tor Anonymity network for command-and-control operations. The malware can also install OpenSSH and activate remote desktop access via RDP on port 3389. Domains such as esetsmart[.]com, esetscanner[.]com, and esetremover[.]com were used to host the malicious software.

InedibleOchotense shows connections to the Sandworm group (also called APT44), which CERT-UA has subdivided into clusters including UAC-0212 and UAC-0125. Sandworm is infamous for its wiper malware campaigns in Ukraine. In April 2025, it deployed wipers named ZEROLOT and Sting targeting a university, followed by further destructive malware attacks on government, energy, logistics, and grain sectors.

Separately, another Russia-aligned actor, RomCom (also known as Storm-0978 or UNC2596), conducted spear-phishing operations in mid-July 2025 using a zero-day vulnerability in WinRAR (CVE-2025-8088, CVSS score 8.8). The exploits targeted financial, manufacturing, defense, and logistics firms in Europe and Canada. Successful intrusions installed backdoors such as SnipBot, RustyClaw, and a Mythic agent, as reported by AttackIQ and ESET.

RomCom has evolved from a cybercrime tool to a utility supporting nation-state objectives, adapting its operations based on geopolitical developments linked to the ongoing conflict in Ukraine, as noted by security researchers.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Tether Sets Two-Week Deadline for $500B Fundraise

Tether is reportedly giving investors a two-week deadline to commit to a $500 billion...

Ethereum Foundation Nears 70K ETH Staking Goal After Latest $92M Batch

The Ethereum Foundation staked over 45,000 ETH, worth more than $92 million, on Friday.This...

Dmail Network Shuts Down After Five-Year Decentralized Run

Decentralized email platform Dmail Network will officially begin ceasing its services on May 15...

Bank of Canada Study: Aave V3 Had Zero Bad Loans in 2024

A Bank of Canada staff analysis found Aave V3 had zero non-performing loans in...

Tech Giants Found AI Payment Protocol Group

The x402 Foundation launched on Thursday by the Linux Foundation to govern an AI...

Must Read

17 Best Cryptocurrency Wallets

If you are looking for a list with the best cryptocurrency wallets, then you've landed on the right page. Cryptocurrency, as we all know,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading