Friday, August 14, 2026
LIVE
Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///
Subscribe
The Levant
Independent · Digital
The Levant Herald
PoliticsAI-assisted

Threat Actors Using Weaponized AV-themed Word and PDF Documents to Attack Israeli Organizations

Security researchers at Seqrite Labs have identified a campaign named Operation IconCat, targeting Israeli organizations with weaponized documents disguised as legitimate security tools.

Security researchers at Seqrite Labs have identified a campaign named Operation IconCat, targeting Israeli organizations with weaponized documents disguised as legitimate security tools.

The attacks commenced in November 2025, compromising multiple companies within the information technology, staffing services, and software development sectors.

The attackers employ a psychological tactic by creating fake documents resembling those of trusted antivirus vendors such as Check Point and SentinelOne. When victims open these disguised files, they inadvertently download malware concealed behind a familiar brand name.

The campaign illustrates how social engineering, combined with technical sophistication, can circumvent traditional security defenses.

Operation IconCat consists of two distinct attack chains, both employing similar tactics but deploying different malware variants.

The first chain utilizes PDF files for document-based delivery, while the second employs Word documents embedded with hidden programming code.

Security researchers at Seqrite Labs have identified a campaign named Operation IconCat, targeting Israeli organizations with weaponized documents disguised as legitimate security tools.
Karim Nasrallah · The Levant Herald

Seqrite analysts identified the malware by analyzing suspicious file uploads from Israel dated November 16 and 17, 2025.

The initial attack wave involves a PDF file named help.pdf, presenting itself as a Check Point security scanner manual. The document instructs users to download a tool named "Security Scanner" from Dropbox, protected with the password "cloudstar." The file includes detailed instructions on performing security scans, complete with authentic-looking screenshots.

This PDF serves as the entry point for deploying PYTRIC, a Python-based malware packaged using PyInstaller technology.

PYTRIC possesses capabilities extending beyond typical malware behavior. Analysis reveals functions designed to scan files across the entire system, check for administrator privileges, and execute destructive actions such as erasing system data and deleting backups.

Advertisement

The malware communicates via a Telegram bot named Backup2040, enabling attackers to remotely control infected machines. This combination suggests an intent not only to steal information but also to destroy it entirely.

The second campaign follows a similar pattern but utilizes a Rust-based implant called RUSTRIC. A spear-phishing email impersonates L.M. Group, a legitimate Israeli human resources company, using the spoofed domain l-m.co.il. The email attachment contains a corrupted Word document with hidden macros that extract and execute the final payload.

RUSTRIC exhibits advanced reconnaissance capabilities, checking for the presence of 28 different antivirus products, including Quick Heal, CrowdStrike, and Kaspersky. Once executed through Windows Management Instrumentation, it runs system commands to identify the infected computer and establish connections to attacker-controlled servers.

Security teams should consider these campaigns as high-priority threats necessitating immediate investigation and remediation efforts.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories