Israeli Organizations Targeted by AV-Themed Malicious Word and PDF Files
SEQRITE Labs' Advanced Persistent Threat (APT) Team has identified a sophisticated campaign targeting Israeli organizations via weaponized Microsoft Word and PDF documents masquerading as legitimate antivirus software.
SEQRITE Labs' Advanced Persistent Threat (APT) Team has identified a sophisticated campaign targeting Israeli organizations via weaponized Microsoft Word and PDF documents masquerading as legitimate antivirus software.
The operation, identified as UNG0801 or "Operation IconCat," exploits the trusted branding of security vendors SentinelOne and Check Point to deploy malicious payloads.
This threat cluster, originating from Western Asia, has been active since mid-November 2025, focusing on Israeli enterprises in the information technology, human resources, and software development sectors.
The campaigns use Hebrew-language phishing lures that replicate routine corporate communications, such as compliance updates and security advisories, to increase victim interaction rates.
Operation IconCat consists of two distinct infection chains, both relying on antivirus icon spoofing.
The first campaign, initiated on November 16, 2025, distributes a malicious PDF titled "help.pdf" that instructs recipients to download a "Security Scanner" from Dropbox using the password "cloudstar." This document features authentic Check Point branding to reinforce its legitimacy.
SEQRITE Labs' Advanced Persistent Threat (APT) Team has identified a sophisticated campaign targeting Israeli organizations via weaponized Microsoft Word and PDF documents masquerading as legitimate antivirus software.
The payload, PYTRIC, is a PyInstaller-packaged Python executable masquerading as a security tool. Technical analysis shows PYTRIC functions as a destructive wiper, capable of system-wide data deletion and communicating with a command-and-control infrastructure via a Telegram bot named "Backup2040."
The second campaign, detected on November 17, 2025, employs spear-phishing emails impersonating L.M. Group, a legitimate Israeli HR firm. These emails carry malicious Word documents and ZIP files with macro-enabled attachments that drop RUSTRIC, a Rust-based reconnaissance implant.
Unlike PYTRIC, RUSTRIC focuses on intelligence gathering, enumerating antivirus products and executing system reconnaissance commands.
Infrastructure analysis reveals differing command-and-control methods. The first campaign uses Telegram for communication, while the second employs a dedicated C2 server with traces of a previous domain, netvigil.org. This suggests the use of repurposed or low-cost virtual private servers.
SEQRITE Labs categorizes both campaigns under the UNG0801 cluster due to shared operational timing, geographic targeting, and consistent misuse of antivirus branding.
Despite this, the differing objectives complicate attribution efforts, suggesting possible collaboration between multiple threat groups or evolving priorities within a single entity.
Organizations in Israel's technology and services sectors should enhance email filtering, disable macro execution by default, and monitor for suspicious activities involving PowerShell and external communications to Telegram or unverified C2 domains.
Based on reporting by GBHackers.




