A spearphishing campaign compromised at least 15 Israeli defense-related computers after targets received a spoofed email posing as a message from Israel's Shin Bet security service. The lure referenced the death of former Prime Minister Ariel Sharon and carried a malicious attachment that installed Xtreme RAT, giving attackers temporary remote control, the ability to execute commands, steal information, and potentially spread further inside affected networks.
Researchers at Seculert said one confirmed victim was Israel's Civil Administration, the agency that manages Palestinian movement and entry permits, while other affected systems were reported to belong to suppliers connected to the Israeli defense forces. The company said it disrupted the operation by sinkholing the malware, but the full scope of data access and lateral movement was not publicly confirmed. Investigators said the campaign resembled a 2012 attack on Israeli government targets, with some assessments pointing to likely pro-Palestinian hackers, though attribution remained unconfirmed.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
By 2014-01-27, Seculert publicly reported the intrusion, describing technical and stylistic similarities to a 2012 attack against Israeli government staff and assessing that pro-Palestinian hackers were likely responsible. Attribution remained unconfirmed, and Israeli officials did not publicly comment.
During its investigation, Israeli security firm Seculert said it disrupted the attack by sinkholing the malware infrastructure, helping contain the threat. The full extent of data theft, lateral movement, or operational impact was still unclear.
In mid-January 2014, the phishing campaign temporarily compromised 15 computers linked to Israel's defense sector. One confirmed victim was Israel's Civil Administration, and other affected systems were reportedly tied to suppliers to the Israeli defense forces.
On 2014-01-15, attackers launched a spearphishing campaign using emails disguised as messages from Israel's Shin Bet security service and themed around the death of former Prime Minister Ariel Sharon. The malicious attachment delivered Xtreme RAT to targeted defense-related systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.