Kalambur

First seen
2017-11-01 00:00:00
Malware type
downloader, trojan
Profile updated
2026-07-07 14:38:35

Context

According to EclecticIQ, Kalambur is designed to gather local system information, then download a repackaged TOR binary inside a ZIP file and retrieve additional tools from what is likely an attacker-controlled TOR onion site.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Ps1.Kalambur (report)
  • blog.eclecticiq.com — Sandworm Apt Targets Ukrainian Users With Trojanized Microsoft Kms Activation Tools In Cyber Espionage Campaigns (report)

External references