InedibleOchotense spear phishing campaign impersonating ESET
Campaign
Summary
Hide ▲
Show ▼
The InedibleOchotense spear phishing campaign impersonating ESET delivered a trojanized installer and Kalambur backdoor, creating a direct infection risk for targeted recipients. The operation used emails and Signal messages to reach victims and blended legitimate-brand trust with malicious payload delivery. That combination raises the chance of stealthy compromise and follow-on intrusion.
Related Happenings
Konni multi-stage KakaoTalk phishing campaign
Campaign
H score31
First: 17.03.2026 11:53
Last: 17.03.2026 11:53
Sources 1
About this happening:
The Konni operation is expanding through spear-phishing and abused KakaoTalk desktop accounts, increasing the chance that one compromise reaches multiple contacts. It...
Konni multi-stage KakaoTalk phishing campaign
CampaignAbout this happening: The Konni operation is expanding through spear-phishing and abused KakaoTalk desktop accounts, increasing the chance that one compromise reaches multiple contacts. It...
Russian state-sponsored hackers' ongoing Signal and WhatsApp phishing campaign
Campaign
H score38
First: 09.03.2026 23:24
Last: 09.03.2026 23:24
Sources 1
About this happening:
An ongoing Russian intelligence-linked phishing campaign is targeting Signal and WhatsApp users and has evolved from stealing verification codes and account PINs t...
Russian state-sponsored hackers' ongoing Signal and WhatsApp phishing campaign
CampaignAbout this happening: An ongoing Russian intelligence-linked phishing campaign is targeting Signal and WhatsApp users and has evolved from stealing verification codes and account PINs t...
Latest development: 27.06.2026 01:06
FBI and CISA warn that the Russian intelligence services-linked Signal phishing campaign has evolved from stealing verification codes, account PINs, and linked-device access to eliciting victims' Backup Recovery Keys through impersonated Signal support messages. If a target provides the key, attackers can restore Signal's Secure Backups on their own devices and read historical messages, including private and group conversations, while the campaign continues to target high-intelligence-value individuals.
Signal phishing campaign targeting senior figures in Germany and Europe
Campaign
H score32
First: 06.02.2026 22:00
Last: 06.02.2026 22:00
Sources 1
About this happening:
A Signal phishing campaign is targeting senior figures in Germany and across Europe, seeking access to one-to-one and group chats plus contact lists. The operation...
Signal phishing campaign targeting senior figures in Germany and Europe
CampaignAbout this happening: A Signal phishing campaign is targeting senior figures in Germany and across Europe, seeking access to one-to-one and group chats plus contact lists. The operation...
Kimsuky QR-code spear-phishing campaign against think tanks and government entities
Campaign
H score42
First: 09.01.2026 07:46
Last: 09.01.2026 07:46
Sources 1
About this happening:
The FBI warned that Kimsuky (APT43) is running a QR-code spear-phishing campaign that targets think tanks, academic institutions, and U.S. and foreign government ent...
Kimsuky QR-code spear-phishing campaign against think tanks and government entities
CampaignAbout this happening: The FBI warned that Kimsuky (APT43) is running a QR-code spear-phishing campaign that targets think tanks, academic institutions, and U.S. and foreign government ent...
Kimsuky QR-phishing campaign distributing DocSwap Android malware
Campaign
H score33
First: 18.12.2025 09:43
Last: 18.12.2025 09:43
Sources 1
About this happening:
The Kimsuky operation now uses QR-code phishing to push DocSwap Android malware, raising the risk of mobile compromise for users drawn in by delivery-themed lures. The...
Kimsuky QR-phishing campaign distributing DocSwap Android malware
CampaignAbout this happening: The Kimsuky operation now uses QR-code phishing to push DocSwap Android malware, raising the risk of mobile compromise for users drawn in by delivery-themed lures. The...
Timeline
-
06.11.2025 14:20 2 articles · 8mo ago
InedibleOchotense impersonates ESET in spear phishing campaign
Initial DisclosureReported on November 6, 2025, InedibleOchotense impersonated ESET in a spear phishing campaign that used emails and Signal messages to deliver a trojanized ESET installer, leading targeted recipients to a legitimate ESET product alongside the Kalambur backdoor.
Show sources
- Russian Hacking Group Sandworm Deploys New Wiper Malware in Ukraine — www.infosecurity-magazine.com — 07.11.2025 14:20
- Russian Hacking Group Sandworm Deploys New Wiper Malware in Ukraine — www.infosecurity-magazine.com — 07.11.2025 14:20