EXECUTIVE SUMMARY
UNG0801 is a persistent threat cluster mainly targeting enterprise environments, with most activity seen against organizations in Israel. The campaigns rely on phishing emails written in Hebrew that closely resemble normal internal communication, such as security notices or routine updates. A clear and repeated pattern is the abuse of antivirus-themed visuals, where trusted security icons and interfaces are spoofed to make malicious content appear safe. Word and PDF files are used as the entry point, acting as decoys that guide users into downloading or running harmful files. Two related campaigns were observed within a short time span and showed strong similarities in delivery style and visual tricks. Although the tools and infrastructure used were different, the shared playbook suggests a common operator or a closely linked group. Based on these overlaps, both campaigns are grouped under a single cluster, with the understanding that this may change as new information emerges. Targeting patterns show a focus on technology-focused businesses, staffing services, and development-related organizations within Israel.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
UNG0801 is a persistent threat cluster mainly targeting enterprise environments, with most activity seen against organizations in Israel. The campaigns rely on phishing emails written in Hebrew that closely resemble normal internal communication, such as security notices or routine updates. A clear and repeated pattern is the abuse of antivirus-themed visuals, where trusted security icons and interfaces are spoofed to make malicious content appear safe. Word and PDF files are used as the entry point, acting as decoys that guide users into downloading or running harmful files. Two related campaigns were observed within a short time span and showed strong similarities in delivery style and visual tricks. Although the tools and infrastructure used were different, the shared playbook suggests a common operator or a closely linked group. Based on these overlaps, both campaigns are grouped under a single cluster, with the understanding that this may change as new information emerges. Targeting patterns show a focus on technology-focused businesses, staffing services, and development-related organizations within Israel.[emaillocker id="1283"]
The analysis reveals two infection paths that begin with phishing but lead to different outcomes. In the first campaign, a malicious PDF works as both a lure and an instruction guide, telling victims to download a fake security tool from a file-sharing service. The document is designed to look like a real security product, complete with scan options and result screens, which helps build trust. The downloaded file is a Python-based executable bundled into a standalone program. Once analyzed, it shows functions that scan files, check system privileges, and carry out destructive actions such as deleting data and removing backups, pointing to wiper-like behavior. The second campaign starts with a phishing email that pretends to be an internal message and delivers document attachments. One document contains macros that rebuild hidden data into a file, save it to disk, and execute it. The final payload is written in Rust and focuses on checking installed security software and maintaining contact with a remote server.
The findings support grouping both campaigns under one cluster due to their shared phishing style, antivirus icon abuse, and close timing. Even though the implants differ in design and purpose, the same visual trick is used to make malicious files look trustworthy. The first campaign appears aimed at disruption, using destructive actions that damage systems, while the second shows signs of spying activity through system checks and ongoing remote control. This suggests that a single playbook is being reused for different goals. Infrastructure review shows signs of reused servers and leftover settings, which points to quick setup rather than careful cleanup. While clear attribution remains difficult, the repeated patterns provide enough confidence to track this activity as one cluster for now, with the understanding that this assessment may change as more evidence becomes available.
THREAT PROFILE:
| Tactic | Technique ID | Sub-Technique | Technique |
| Initial Access | T1566.001 | Spearphishing Attachment | Phishing |
| T1566.002 | Spearphishing Link | Phishing | |
| T1204.002 | Malicious File | User Execution | |
| Execution | T1059.006 | Python | Command and Scripting Interpreter |
| T1059.005 | Visual Basic | Command and Scripting Interpreter | |
| T1047 | — | Windows Management Instrumentation | |
| Defense Evasion | T1036.005 | Match Legitimate Name or Location | Masquerading |
| T1027 | — | Obfuscated Files or Information | |
| T1218 | — | Signed Binary Proxy Execution | |
| Discovery | T1518.001 | Security Software Discovery | Software Discovery |
| Command and Control | T1105 | — | Ingress Tool Transfer |
| T1071.001 | Web Protocols | Application Layer Protocol |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]