Security1 distinct publisher2 min readPublished
A publication ban lifted this week on the case Profero opened in April, when its responders pulled a 101MB RAT that had reportedly reached dozens of Israeli companies through a security vendor's own endpoint component.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The operator's own tooling logged him. Profero, the Israeli incident response firm founded in 2020 by Omri Segev Moyal and Guy Barnhart-Magen [20], says the sample it recovered in April carried a Discord bot token in plaintext inside the binary [11]. Discord was the malware's primary command channel, with MQTT secondary and Telegram as an optional backup [12]. That gave the responders the attacker's management channel. They logged his working hours, and their monitoring alerted every time he pushed a new build to victims [18]. From there they reached a partial identification of the man and a confirmed identification of some of the victims [23], and took it to the National Cyber Directorate and Israel Police [17].
Profero's first public writeup went up on April 28 [12]. The thread describing the plaintext token came on August 24 [11]. That is 118 days between the two: 2 days left in April, 31 in May, 30 in June, 31 in July, 24 in August [22]. The court order barring publication of the case came off only on Tuesday night, and at his lawyer's request the suspect's name is still withheld [6].
The delivery path is the thinnest part of the public record and the most consequential. Segev Moyal told People and Computers that victims were infected through an endpoint protection component belonging to an Israeli cyber unicorn, which he did not name [15]. Once resident, the malware stole credentials and abused Active Directory [12]. Neither the vendor's identity nor the mechanism by which its component carried the payload is public.
The employment claim also rests on one publisher. People and Computers reports the suspect is a computer expert who worked as an information security man at a large Israeli integration company [2], while Segev Moyal's own phrasing was that the suspect had worked at, or been dismissed from, the integration firm [21]. Investigators say he acted on his own and has no criminal record [5]. The offenses attributed to him so far are under the Computer Law, plus wiretapping and invasion of privacy [4].
Profero says it briefly suspected an Iranian build [14]. Its later read was a developer who was not technically strong, leaning on AI and vibe coding tools [10] and on software associated with gaming [16]. That construction still bought administrative access in several organizations, at a level Profero says could have supported ransomware [19]. Nobody has said publicly whether the integrator's client list overlaps the victim list. Police have already searched several additional companies [8].
Ranked by verification strength, evidence, and original report placement.
In a thread dated August 24, 2026, Profero said that back in April it pulled a malware sample off a victim host and found a Discord bot token sitting in plaintext in the binary.
Profero's May 1 post said tracking the malware produced a precise timeline of the attacker's tools that he could not fake or clean up, that it followed his activity, working hours and victims, that its monitoring alerted each time he pushed a new version of the malware to victims, and that it identified some unique victims with certainty.
Profero's May 1 post said the campaign was not small, that the threat actor aimed to hit as many organizations as possible, and that the attacker held administrator-level access in several organizations, a level of access that could support ransomware.
Segev Moyal called it a severe incident that could have been catastrophic for the economy, and said the suspect is someone who apparently worked at, or was dismissed from, the integration company.
Through data collection and cross-referencing, Profero's researchers reached a partial identification of the hacker and an identification of some of the victims.
An Ashkelon resident in his 40s was arrested on suspicion of breaking into dozens, or hundreds, of Israeli companies across all sectors of the economy and planting malware to collect sensitive information.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 30, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
GTA VI leak: extortion leverage moves from the regulator to the fanbase1 distinct publisher
build
OpenClaw makes the channel the architecture, and the reasoning loop a lodger1 distinct publisher
build
The 84% a wallet will not show you: DFK Chain's sunset is an address problem1 distinct publisher
security
North Korea's hiring funnel: 60 applications a day, 22 personas, ten jobs landed1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One outlet, one responder, no second voice
The procedural spine is solid and checkable in principle — a named unit, a named court, a defined offence list, a dated gag lift — and People and Computers reports it as its own work. Everything that makes the case frightening comes from Profero's blog posts and social threads, quoted at length rather than tested: the delivery path, the victim count, the ransomware-grade access. No police spokesperson, no affected company, no vendor and no defence lawyer speaks anywhere in this reporting.
Real hosts, real court dates, fuzzy denominator
This is not a proposal or a product launch; things happened. A file was recovered from a live victim, versions were pushed and observed in flight, admin access existed at multiple organisations, machines are being rebuilt, a suspect is in custody and police widened searches to other companies. What refuses to firm up is the footprint: 'many dozens, possibly a few hundred' is a four-fold range from the firm that counted, with not a single infected organisation identified.
Catastrophe framing outruns the artefacts
Strip the adjectives and a competent insider-threat case remains, with genuinely good tracking work behind it. But the phrases doing the emotional labour — catastrophic for the economy, written by AI, delivered through a unicorn's own endpoint agent, perhaps a few hundred victims — all originate with the responder who worked the case, and none is pinned to a document a reader can open. The plaintext bot token is a nice detail that cuts the other way: the operator was sloppy enough to be watched for months.
The firm that found it also frames it
Profero sells incident response, brought the case to the National Cyber Directorate and police, and supplies nearly every technical and evaluative sentence here; its own thread opens by noting how rarely it can talk about an engagement publicly. Two other interests shape what is missing: the implicated cyber unicorn stays unnamed, and the suspect's name stays suppressed because his lawyer asked. The outlet's own incentive is visible in the framing as an exposé for the Israeli security profession.
Firm on the courtroom, soft on the cause
I would repeat the enforcement facts without hedging and the malware's shape with light hedging. I would not repeat the victim range, the AI authorship or the EDR delivery path without saying who claims them. That split — verifiable process, unverified mechanism — is what holds the number below halfway, and a single publisher with no corroborating account keeps it there.