Threat Actors Using Weaponized AV-themed Word and PDF Documents to Attack Israeli Organizations
Security researchers at Seqrite Labs have identified a campaign named Operation IconCat, targeting Israeli organizations with weaponized documents disguised as legitimate security tools.
Security researchers at Seqrite Labs have identified a campaign named Operation IconCat, targeting Israeli organizations with weaponized documents disguised as legitimate security tools.
The attacks commenced in November 2025, compromising multiple companies within the information technology, staffing services, and software development sectors.
The attackers employ a psychological tactic by creating fake documents resembling those of trusted antivirus vendors such as Check Point and SentinelOne. When victims open these disguised files, they inadvertently download malware concealed behind a familiar brand name.
The campaign illustrates how social engineering, combined with technical sophistication, can circumvent traditional security defenses.
Operation IconCat consists of two distinct attack chains, both employing similar tactics but deploying different malware variants.
The first chain utilizes PDF files for document-based delivery, while the second employs Word documents embedded with hidden programming code.
Security researchers at Seqrite Labs have identified a campaign named Operation IconCat, targeting Israeli organizations with weaponized documents disguised as legitimate security tools.
Seqrite analysts identified the malware by analyzing suspicious file uploads from Israel dated November 16 and 17, 2025.
The initial attack wave involves a PDF file named help.pdf, presenting itself as a Check Point security scanner manual. The document instructs users to download a tool named "Security Scanner" from Dropbox, protected with the password "cloudstar." The file includes detailed instructions on performing security scans, complete with authentic-looking screenshots.
This PDF serves as the entry point for deploying PYTRIC, a Python-based malware packaged using PyInstaller technology.
PYTRIC possesses capabilities extending beyond typical malware behavior. Analysis reveals functions designed to scan files across the entire system, check for administrator privileges, and execute destructive actions such as erasing system data and deleting backups.
The malware communicates via a Telegram bot named Backup2040, enabling attackers to remotely control infected machines. This combination suggests an intent not only to steal information but also to destroy it entirely.
The second campaign follows a similar pattern but utilizes a Rust-based implant called RUSTRIC. A spear-phishing email impersonates L.M. Group, a legitimate Israeli human resources company, using the spoofed domain l-m.co.il. The email attachment contains a corrupted Word document with hidden macros that extract and execute the final payload.
RUSTRIC exhibits advanced reconnaissance capabilities, checking for the presence of 28 different antivirus products, including Quick Heal, CrowdStrike, and Kaspersky. Once executed through Windows Management Instrumentation, it runs system commands to identify the infected computer and establish connections to attacker-controlled servers.
Security teams should consider these campaigns as high-priority threats necessitating immediate investigation and remediation efforts.
Based on reporting by Cyber Security News.




