logo

Threat Actors Using Weaponized AV-themed Word and PDF Documents to Attack Israeli Organizations

ID: 94b39898-09f2-5097-a649-4efd0f397e28

STIX ID: report--94b39898-09f2-5097-a649-4efd0f397e28

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-12-24

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Operation IconCat is a targeted campaign against Israeli organizations that uses spoofed antivirus-branded documents (PDF and Word) to deliver two malware variants: PYTRIC (Python/PyInstaller) — capable of system-wide scanning, privilege checks, data destruction and backup deletion with Telegram-based C2 — and RUSTRIC (Rust) — which performs AV fingerprinting across 28 products, executes via WMI, and establishes connections to attacker servers; initial infections were observed in November 2025 via spear-phishing and password-protected Dropbox downloads, and security teams are advised to prioritize investigation and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.