Threat actors have launched a sophisticated campaign, dubbed Operation IconCat, targeting Israeli organizations across sectors such as information technology, staffing services, and software development. The attackers use weaponized Word and PDF documents that impersonate trusted antivirus vendors like Check Point and SentinelOne, leveraging social engineering to bypass security defenses. Victims are lured into opening these documents, which then deliver malware payloads, including a Python-based implant called PYTRIC and a Rust-based implant named RUSTRIC. The campaign employs two main infection chains: one using PDF files as decoys to distribute malware via Dropbox, and another using malicious Word documents with embedded code. Both chains exploit AV icon spoofing to increase credibility and user interaction.
Researchers at Seqrite Labs have identified that the threat cluster, tracked as UNG0801, is likely based in Western Asia and demonstrates a persistent focus on Israeli enterprise environments. The phishing lures are crafted in Hebrew and mimic routine internal communications, such as compliance updates and security advisories. The campaign's technical sophistication includes the use of PyInstaller for packaging malware, system-wide file scanning, privilege escalation checks, and destructive capabilities like system erasure. Indicators of compromise and MITRE ATT&CK mappings have been published to aid defenders in detection and response efforts.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Seqrite Labs published its research on UNG0801/Operation IconCat, linking the two campaigns through shared tactics, techniques, infrastructure, and timing despite their differing goals of espionage and destruction. The company also released detection signatures and indicators of compromise for both malware delivery chains.
In a parallel campaign, spear-phishing emails impersonating legitimate Israeli companies delivered macro-enabled Word documents that installed the Rust-based RUSTRIC implant. RUSTRIC performed host and network reconnaissance, enumerated 28 AV/EDR products, and communicated with attacker-controlled command-and-control servers.
In one campaign, attackers used malicious PDF files themed around trusted AV vendors such as Check Point and SentinelOne to deliver a PyInstaller-packed Python wiper dubbed PYTRIC. The malware was designed for destructive impact, including wiping system data, and used Dropbox plus Telegram-based or custom infrastructure for delivery and control.
Seqrite Labs said the threat cluster it tracks as UNG0801, also called Operation IconCat, began two related campaigns against Israeli organizations in November 2025. The activity targeted sectors including IT, HR, and software development using Hebrew-language phishing lures and spoofed antivirus branding.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.