Actors Insights|Latest update04/07/2026

UNG0801

Named by SeqriteSuspected state sponsor: Islamic Republic of Iran

UNG0801 is SEQRITE Labs' designation for a previously unknown threat cluster, also tracked as Operation IconCat, first observed in mid-November 2025 targeting Israeli organizations across IT, human resources, and software development sectors. The group is believed to originate from Western Asia and uses Hebrew-language spear-phishing emails impersonating internal corporate communications to deliver malicious Word and PDF documents. A distinctive characteristic is the group's consistent abuse of antivirus vendor branding — specifically spoofing Check Point and SentinelOne icons — to create false legitimacy for malicious payloads. Two distinct infection chains were identified: PYTRIC, a PyInstaller-based implant with system-wiping capabilities, and RUSTRIC, a Rust-based reconnaissance tool that enumerates 28 antivirus and EDR products before executing system discovery commands. PYTRIC communicates via Telegram while RUSTRIC uses attacker-controlled command and control infrastructure. Despite sharing a common AV icon-spoofing playbook, the dual objectives suggest potential collaboration between subgroups or evolving operational priorities within the cluster.

First Seen:Nov 2025
Last Seen:Dec 2025
Indexed Reports:1
Public IOCs:8
Cluster: Unclassified
also known as:
UNG0801

Targeted Regions

Israel
IL
Israel
Israel
Nov 2025 ~ Dec 2025
Nov 2025 ~ Dec 2025
Jan 2025Dec 2026

Targeted Sectors

Information TechnologyProfessional Service

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.