An unidentified threat actor targeting Israel's critical sectors with SysJoker malware.
Analyst brief
WildCard is an unidentified threat actor that initially targeted Israel's educational sector with SysJoker malware. They primarily focus on targeting critical sectors within Israel, expanding from education to potentially other key infrastructure. Their main TTPs involve deploying custom malware variants like RustDown—written in the Rust programming language—and disguising malicious payloads as legitimate software. Defenders should monitor for unusual process executions, especially Rust-based binaries, and scrutinize anomalous network traffic for C2 patterns associated with SysJoker infections.
WildCard
activeunknown
Wildcard is a threat actor that initially targeted Israel's educational sector with the SysJoker malware. They have since expanded their operations and developed additional malware variants, disguised as legitimate software, including one written in the Rust programming language called RustDown. Their precise identity remains unknown, but they have shown advanced capabilities and a focus on critical sectors within Israel.