Skip to content
Russia-Linked Group Targets Ukraine with Phishing Attacks Using Trojanized Software

Russia-Linked Group Targets Ukraine with Phishing Attacks Using Trojanized Software

First seen 2 Dec 2025, 18:33 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

In May 2025, the Russia-linked group InedibleOchotense conducted phishing attacks on Ukrainian targets using trojanized ESET installers. These attacks involved delivering malicious software through emails and Signal messages, which installed both legitimate software and the Kalambur backdoor. The broader context includes increased espionage and cybercrime activities by state-aligned hacking groups over the past six months.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 194d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track Kalambur in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed