UNG0801
Named by SeqriteSuspected state sponsor: Islamic Republic of IranUNG0801 is SEQRITE Labs' designation for a previously unknown threat cluster, also tracked as Operation IconCat, first observed in mid-November 2025 targeting Israeli organizations across IT, human resources, and software development sectors. The group is believed to originate from Western Asia and uses Hebrew-language spear-phishing emails impersonating internal corporate communications to deliver malicious Word and PDF documents. A distinctive characteristic is the group's consistent abuse of antivirus vendor branding — specifically spoofing Check Point and SentinelOne icons — to create false legitimacy for malicious payloads. Two distinct infection chains were identified: PYTRIC, a PyInstaller-based implant with system-wiping capabilities, and RUSTRIC, a Rust-based reconnaissance tool that enumerates 28 antivirus and EDR products before executing system discovery commands. PYTRIC communicates via Telegram while RUSTRIC uses attacker-controlled command and control infrastructure. Despite sharing a common AV icon-spoofing playbook, the dual objectives suggest potential collaboration between subgroups or evolving operational priorities within the cluster.
Targeted Regions
IsraelIsrael
Nov 2025 ~ Dec 2025
Nov 2025 ~ Dec 2025
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.