Friday, August 14, 2026
LIVE
Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///
Subscribe
The Levant
Independent · Digital
The Levant Herald
PoliticsAI-assisted

Israeli Organizations Targeted by AV-Themed Malicious Word and PDF Files

SEQRITE Labs' Advanced Persistent Threat (APT) Team has identified a sophisticated campaign targeting Israeli organizations via weaponized Microsoft Word and PDF documents masquerading as legitimate antivirus software.

SEQRITE Labs' Advanced Persistent Threat (APT) Team has identified a sophisticated campaign targeting Israeli organizations via weaponized Microsoft Word and PDF documents masquerading as legitimate antivirus software.

The operation, identified as UNG0801 or "Operation IconCat," exploits the trusted branding of security vendors SentinelOne and Check Point to deploy malicious payloads.

This threat cluster, originating from Western Asia, has been active since mid-November 2025, focusing on Israeli enterprises in the information technology, human resources, and software development sectors.

The campaigns use Hebrew-language phishing lures that replicate routine corporate communications, such as compliance updates and security advisories, to increase victim interaction rates.

Operation IconCat consists of two distinct infection chains, both relying on antivirus icon spoofing.

The first campaign, initiated on November 16, 2025, distributes a malicious PDF titled "help.pdf" that instructs recipients to download a "Security Scanner" from Dropbox using the password "cloudstar." This document features authentic Check Point branding to reinforce its legitimacy.

SEQRITE Labs' Advanced Persistent Threat (APT) Team has identified a sophisticated campaign targeting Israeli organizations via weaponized Microsoft Word and PDF documents masquerading as legitimate antivirus software.
Yara Mansour · The Levant Herald

The payload, PYTRIC, is a PyInstaller-packaged Python executable masquerading as a security tool. Technical analysis shows PYTRIC functions as a destructive wiper, capable of system-wide data deletion and communicating with a command-and-control infrastructure via a Telegram bot named "Backup2040."

The second campaign, detected on November 17, 2025, employs spear-phishing emails impersonating L.M. Group, a legitimate Israeli HR firm. These emails carry malicious Word documents and ZIP files with macro-enabled attachments that drop RUSTRIC, a Rust-based reconnaissance implant.

Unlike PYTRIC, RUSTRIC focuses on intelligence gathering, enumerating antivirus products and executing system reconnaissance commands.

Infrastructure analysis reveals differing command-and-control methods. The first campaign uses Telegram for communication, while the second employs a dedicated C2 server with traces of a previous domain, netvigil.org. This suggests the use of repurposed or low-cost virtual private servers.

Advertisement

SEQRITE Labs categorizes both campaigns under the UNG0801 cluster due to shared operational timing, geographic targeting, and consistent misuse of antivirus branding.

Despite this, the differing objectives complicate attribution efforts, suggesting possible collaboration between multiple threat groups or evolving priorities within a single entity.

Organizations in Israel's technology and services sectors should enhance email filtering, disable macro execution by default, and monitor for suspicious activities involving PowerShell and external communications to Telegram or unverified C2 domains.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories