RUSTRIC
RUSTRIC is a Rust-based implant/RAT associated with SEQRITE-tracked UNG0801 in Operation IconCat, observed targeting Israeli organizations since November 2025. Reporting describes it as an espionage-focused malware used to steal sensitive data. The malware was delivered in a phishing campaign using Hebrew-language lures and spear-phishing emails, including messages impersonating the Israeli HR company L.M. Group, with a malicious Microsoft Word document containing macros that extracts and launches the payload. The campaign spoofed SentinelOne branding and iconography so the implant appeared to be a legitimate security-related binary. RUSTRIC performs reconnaissance and host identification, including gathering basic system information, running commands via Windows Management Instrumentation, and enumerating the presence of 28 antivirus/EDR products, with examples including Quick Heal, CrowdStrike, and Kaspersky. It then establishes command-and-control communications with attacker-controlled servers over HTTPS/port 443. Reported victim sectors include Israeli IT, HR/staffing, software development, and more broadly Israeli organizations. Infrastructure reporting tied the campaign to netvigil.org certificate residue and included IOC examples such as stratioai[.]org and 159[.]198[.]68[.]25. Attribution remains not definitive, but SEQRITE assessed the broader UNG0801 cluster as likely originating from Western Asia.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...Rust based implant, which we have decided to term as RUSTRIC..."
Techniques & procedures
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Stealth
1 technique
Stealth
Discovery
2 techniques
Discovery
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Rust-based RAT used against Israeli organizations, supporting reconnaissance, AV enumeration, and C2 communications; later linked to RustyWater/Archer RAT reporting.
A Rust-based implant used in phishing-led intrusions, masquerading as a legitimate binary via AV vendor icon spoofing (SentinelOne) as part of 'Operation IconCat'/UNG0801 activity.
Rust-based implant that enumerates antivirus programs, collects system information, and communicates with external servers.
Rust-based implant delivered via spear-phishing Word documents with macros, used for system reconnaissance, antivirus detection, and establishing remote access to attacker infrastructure.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.