logo

UNG0801: Tracking Threat Clusters obsessed with AV Icon Spoofing targeting Israel

ID: 73dd2d6d-4d14-526b-8272-fee12bdb83df

STIX ID: report--73dd2d6d-4d14-526b-8272-fee12bdb83df

Feed Name: Seqrite Blog

Threat Score
80/100

Date Published: 2025-12-22

Date Updated: 2026-04-30

Author: Priya Patel

...
...

SEQRITE Labs documents Operation IconCat (UNG0801), a targeted spear-phishing campaign against Israeli enterprise organizations that uses Hebrew social engineering and antivirus-icon spoofing to deliver two distinct implants: PYTRIC (a PyInstaller-packaged Python wiper distributed via a malicious PDF and Dropbox link) and RUSTRIC (a Rust implant delivered via malicious Word macros that enumerates AV/EDR products and connects to C2). The report provides technical analysis of payloads, infrastructure and C2 artifacts, IOCs (hashes, domains, IPs), and a mapped MITRE ATT&CK matrix, concluding the activity resembles APT-style operations with both destructive and espionage objectives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.