News room

Israeli Cybersecurity Specialist Arrested for WindowsAudit RAT Campaign and Israeli Payment Card Data Sale

Israeli law enforcement arrested a 40-year-old cybersecurity specialist from Ashkelon on August 18, 2026, for allegedly deploying WindowsAudit RAT malware against at least 25 Israeli organizations, with potential victims numbering in the dozens or hundreds. The arrest represents a significant insider threat case where a trusted security professional allegedly exploited their position to conduct widespread corporate espionage. Concurrently, threat actor 'Fidel' is allegedly selling 150 full CVV records with complete PII from Israeli cardholders, sourced via network sniffing between July and early August 2026. These incidents highlight critical vulnerabilities in Israeli organizations' security posture, particularly regarding insider threats and payment card data protection. The WindowsAudit campaign's operational security failure—unencrypted Discord tokens—enabled threat intelligence researchers to map the attacker's infrastructure, demonstrating how even sophisticated attacks can be undermined by basic security oversights. Organizations must prioritize insider threat detection, network segmentation, and payment card data security controls.

  • A 40-year-old Israeli cybersecurity specialist was allegedly arrested on August 18, 2026, for deploying WindowsAudit RAT malware against at least 25 Israeli organizations, with the actual victim count potentially reaching dozens or hundreds
  • The alleged attacker reportedly obtained domain administrator privileges in some networks, sufficient for ransomware deployment, though no extortion attempts were detected at the time of arrest
  • WindowsAudit RAT allegedly used Discord as primary C2, MQTT as backup, and Telegram as tertiary channel, with capabilities including credential theft, Active Directory manipulation, keylogging, EDR evasion, and WireGuard tunneling
  • Threat actor 'Fidel' is allegedly selling 150 Israeli payment card records with full CVV and PII (address, email, phone, IP, user agent) for $1000-$3000, claimed to be sourced from their own network sniffer between July and early August 2026
  • The WindowsAudit campaign's critical OPSEC failure—unencrypted Discord bot tokens—allegedly allowed Profero to observe the attacker's infrastructure and collect evidence linking infections to specific organizations

Share

Skip to content