Threat Actors Using Weaponized AV-themed Word and PDF Documents to Attack Israeli Organizations
ID: 94b39898-09f2-5097-a649-4efd0f397e28
STIX ID: report--94b39898-09f2-5097-a649-4efd0f397e28
Feed Name: cybersecurityNews.com
Operation IconCat is a targeted campaign against Israeli organizations that uses spoofed antivirus-branded documents (PDF and Word) to deliver two malware variants: PYTRIC (Python/PyInstaller) — capable of system-wide scanning, privilege checks, data destruction and backup deletion with Telegram-based C2 — and RUSTRIC (Rust) — which performs AV fingerprinting across 28 products, executes via WMI, and establishes connections to attacker servers; initial infections were observed in November 2025 via spear-phishing and password-protected Dropbox downloads, and security teams are advised to prioritize investigation and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
