In late April, a client sent Profero’s IR team a file they didn’t like the look of. We wrote about what we found in part one: an unfamiliar .NET backdoor, WindowsAudit.exe, running as LocalSystem and using Discord as its main control channel. In part two, we covered what came next: building a monitor around the attacker’s own infrastructure, pulling their loot dump, and identifying more than two dozen victim organizations.
Last week, that case became something we hadn’t planned to write about. Israeli police announced the arrest of a man in his 40s from Ashkelon, on suspicion of planting malware across dozens of Israeli companies and using it to collect sensitive data. According to Calcalist and the Times of Israel, detectives from the police cyber unit, Lahav 433, made the arrest, searched the suspect’s home, and seized computing equipment. He has been questioned on suspicion of offenses under Israel’s Computers Law, illegal wiretapping, and privacy violations. As of this writing, he has not been charged or convicted of anything, and Israeli reporting notes he has no prior criminal record and is believed, at this stage, to have acted alone.
We’re not naming him. His identity is still covered by a partial publication ban in Israel. What we can talk about, because it’s our own work, is how a file-check request in April turned into a referral that a national cyber unit could actually act on.
From a file check to a nationwide case
The malware itself wasn’t the hard part to find. It was unusual: not a commodity RAT, built with the help of AI coding tools, and distributed in part through channels nobody would expect, gaming utilities and children’s software among them. What took longer was tracing how far it had spread.
Part of the distribution path traced back to a legitimate security component already deployed inside victim networks. We’re not naming the vendor here. It hasn’t been publicly confirmed for release.
As we described in part two, monitoring the attacker’s own command channel let us build a hard, attacker-can’t-fake-it timeline of the campaign:
- when infrastructure was created
- when new victims appeared
- and what access the attacker had achieved
By the time the picture was complete, we’d identified 25 confirmed victim organizations across Israeli industry, some with domain admin access in play, which is the kind of foothold that supports a ransomware deployment, and not just data theft.
That’s the point where we stopped treating this as a contained incident and started treating it as a case. We coordinated notifications through CERT-IL, Israel’s national cybersecurity response team, and handed our findings to the police cyber unit.
Finding malware and building a case are not the same job
Most IR engagements end when the incident is contained: the backdoor is removed, credentials are rotated, and the client gets a report. Getting from there to an arrest requires a different kind of rigor, the kind that holds up outside your own SOC.
A few things mattered here that don’t always get asked for in a standard engagement:
- A verifiable timeline the attacker had no way to forge or scrub after the fact, built from metadata rather than log files the attacker could have touched.
- A documented method for attributing specific technical artifacts, hostnames, domain names, screenshots, to specific named organizations, rather than an anonymized indicator list.
- A clear, defensible account of what data we touched and why, since anything used to support a police referral has to survive scrutiny in a way an internal incident report doesn’t.
None of that is unusual. It’s the difference between forensics done to stop the bleeding, and forensics done to also support what comes after: a referral, an investigation, and eventually, if the evidence holds, an arrest.
The part of this that’s genuinely uncomfortable
Israeli press reporting on the case, which we can’t independently verify beyond what’s public, describes the suspect as someone who worked in information security himself, by day a practitioner, allegedly by night the operator behind the campaign. Omri Segev Moyal, our co-founder and CEO, led the investigation, and even for him, the scale of it was hard to sit with, and was blunt about it in comments reported by Israeli media:
“To call this shocking would be an understatement,” he said, describing an incident he called more serious than it first appeared. Segev Moyal has also said his team initially wondered whether the malware was Iranian state work before the investigation pointed elsewhere entirely.
There’s a version of this story that leans into that irony for its own sake. We’d rather sit with the actual implication: expertise and access are not the same thing as trustworthiness, and the tooling that made this campaign possible, off-the-shelf AI coding assistance, lowered the bar for someone who, by the account so far, didn’t need deep technical skill to build something that reached dozens of organizations. Detection and response can’t be designed around an assumption about who the attacker is. Sometimes the attacker already has a badge.
What this means if you’re evaluating an IR partner
Most breach-readiness conversations focus on speed: how fast can you detect, how fast can you respond, how fast can you get back to operating. Those numbers matter. What this case adds is a less commonly asked question: if it came to it, could your IR partner’s work actually support a criminal referral, not just a technical writeup?
That’s a different bar than containment. It means the difference between a partner who can tell you what happened and one who can build a record that a prosecutor’s cyber division, or your own insurer, or your board, can rely on months later. It’s worth asking directly, before you need the answer.
We wrote about the broader readiness gap in A Breach Is Inevitable, which goes into why most organizations still aren’t set up to detect proactively, let alone build a case after the fact. If you want to talk through where your own organization stands, talk to us.
This is part three of a series. Part one covers the malware itself; part two covers how we tracked the attacker.

