Skip to content

Malware

Kalambur

According to EclecticIQ, Kalambur is designed to gather local system information, then download a repackaged TOR binary inside a ZIP file and retrieve additional tools from what is likely an attacker-

Kalambur is a PowerShell malware family operated by Sandworm.

Background

EclecticIQ reports that Kalambur first collects local system details, then pulls down a repackaged TOR binary delivered in a ZIP archive and fetches further tooling from what is probably an attacker-run TOR onion site.


Source: Malpedia (Fraunhofer FKIE).