PULSE NAME
UNG0801: Tracking Threat Clusters obsessed with AV Icon Spoofing targeting Israel
WHITE UNG0801 AlienVault 2025-12-22 Modified: 2026-01-21
15
IOCs
MEDIUM VOLUME
An analysis of threat clusters, dubbed UNG0801 or Operation IconCat, targeting Israeli organizations. The actors use socially engineered phishing lures in Hebrew, exploiting antivirus icon spoofing from well-known vendors like SentinelOne and Check Point. Two distinct infection chains were identified, both utilizing AV-themed decoys dropped by malicious Word and PDF documents. The first campaign deploys a PyInstaller-based implant called PYTRIC, capable of system-wide wipes and backup deletion. The second campaign uses a Rust-based implant named RUSTRIC, focusing on antivirus enumeration and system information gathering. Both campaigns share similar tactics but differ in their ultimate objectives, with the first aimed at destruction and the second at espionage.
Indicators of Compromise (15)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 3c2fd296da55d1398edd7b6bb375a960 2025-12-22
FileHash-MD5 7f4ded56abaacb2bf4649665ac259c7c 2025-12-22
FileHash-MD5 f06e30dee8629e951cefa73373fdef9d 2025-12-22
FileHash-MD5 f97650ede0c39a29b0b5c5472f685d11 2025-12-22
FileHash-SHA1 25f27131e8de91f8d6fdf9bfa1901577f992ce33 2025-12-22
FileHash-SHA1 6071349b86368768365d4a926e75f2972410fa04 2025-12-22
FileHash-SHA1 8ef8d08d98a7680d1cc7f3a367813e5568b2033d 2025-12-22
FileHash-SHA1 d6ae00e158a266eb8427b61ce06ea8f9468bc7b2 2025-12-22
FileHash-SHA256 2afcac3231235b5cea0fc702d705ec76afec424a9cec820749b83b6299d1fe1b 2025-12-22
FileHash-SHA256 54ebdea80d30660f1d7be0b71bc3eb04189ef2036cdbba24d60f474547d3516a 2025-12-22
FileHash-SHA256 6df21646d13c5b68c14c70516dfc74ef2aef4a4246970d7f4fbd072053ba40e6 2025-12-22
FileHash-SHA256 6f079c1e2655ed391fb8f0b6bfafa126acf905732b5554f38a9d32d0b9ca407d 2025-12-22
FileHash-SHA256 77ceeb88a1fe4fb03af1acc589e02aeb156e3b22b110124ce1b25c940b0d9bbe 2025-12-22
FileHash-SHA256 e422c2f25fbb4951f069c6ba24e9b917e95edb9019c10d34de4309f480c342df 2025-12-22
domain stratioai.org 2025-12-22