Threat Advisory

AV Icon Spoofing Drives Operation IconCat Campaign

Threat: Malicious Campaign
Targeted Region: Isarel
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

UNG0801 is a persistent threat cluster mainly targeting enterprise environments, with most activity seen against organizations in Israel. The campaigns rely on phishing emails written in Hebrew that closely resemble normal internal communication, such as security notices or routine updates. A clear and repeated pattern is the abuse of antivirus-themed visuals, where trusted security icons and interfaces are spoofed to make malicious content appear safe. Word and PDF files are used as the entry point, acting as decoys that guide users into downloading or running harmful files. Two related campaigns were observed within a short time span and showed strong similarities in delivery style and visual tricks. Although the tools and infrastructure used were different, the shared playbook suggests a common operator or a closely linked group. Based on these overlaps, both campaigns are grouped under a single cluster, with the understanding that this may change as new information emerges. Targeting patterns show a focus on technology-focused businesses, staffing services, and development-related organizations within Israel.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

UNG0801 is a persistent threat cluster mainly targeting enterprise environments, with most activity seen against organizations in Israel. The campaigns rely on phishing emails written in Hebrew that closely resemble normal internal communication, such as security notices or routine updates. A clear and repeated pattern is the abuse of antivirus-themed visuals, where trusted security icons and interfaces are spoofed to make malicious content appear safe. Word and PDF files are used as the entry point, acting as decoys that guide users into downloading or running harmful files. Two related campaigns were observed within a short time span and showed strong similarities in delivery style and visual tricks. Although the tools and infrastructure used were different, the shared playbook suggests a common operator or a closely linked group. Based on these overlaps, both campaigns are grouped under a single cluster, with the understanding that this may change as new information emerges. Targeting patterns show a focus on technology-focused businesses, staffing services, and development-related organizations within Israel.[emaillocker id="1283"]

The analysis reveals two infection paths that begin with phishing but lead to different outcomes. In the first campaign, a malicious PDF works as both a lure and an instruction guide, telling victims to download a fake security tool from a file-sharing service. The document is designed to look like a real security product, complete with scan options and result screens, which helps build trust. The downloaded file is a Python-based executable bundled into a standalone program. Once analyzed, it shows functions that scan files, check system privileges, and carry out destructive actions such as deleting data and removing backups, pointing to wiper-like behavior. The second campaign starts with a phishing email that pretends to be an internal message and delivers document attachments. One document contains macros that rebuild hidden data into a file, save it to disk, and execute it. The final payload is written in Rust and focuses on checking installed security software and maintaining contact with a remote server.

The findings support grouping both campaigns under one cluster due to their shared phishing style, antivirus icon abuse, and close timing. Even though the implants differ in design and purpose, the same visual trick is used to make malicious files look trustworthy. The first campaign appears aimed at disruption, using destructive actions that damage systems, while the second shows signs of spying activity through system checks and ongoing remote control. This suggests that a single playbook is being reused for different goals. Infrastructure review shows signs of reused servers and leftover settings, which points to quick setup rather than careful cleanup. While clear attribution remains difficult, the repeated patterns provide enough confidence to track this activity as one cluster for now, with the understanding that this assessment may change as more evidence becomes available.

THREAT PROFILE:

Tactic Technique ID Sub-Technique Technique
Initial Access T1566.001 Spearphishing Attachment Phishing
T1566.002 Spearphishing Link Phishing
T1204.002 Malicious File User Execution
Execution T1059.006 Python Command and Scripting Interpreter
T1059.005 Visual Basic Command and Scripting Interpreter
T1047 Windows Management Instrumentation
Defense Evasion T1036.005 Match Legitimate Name or Location Masquerading
T1027 Obfuscated Files or Information
T1218 Signed Binary Proxy Execution
Discovery T1518.001 Security Software Discovery Software Discovery
Command and Control T1105 Ingress Tool Transfer
T1071.001 Web Protocols Application Layer Protocol

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu