Also known as: Ashen Lepus, network, software application, tracked as, a pen name, NosyDoor, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, a botnet, root access
WIRTE is a state‑aligned cyberespionage actor believed to operate as part of the Hamas‑affiliated Gaza Cybergang. Since August 2018 it has carried out sophisticated social engineering campaigns against diplomatic, financial, military, legal, technology and critical‑infrastructure entities across the Middle East, North Africa and Europe. The group’s tactics blend classic spearphishing—using compromised email accounts and malicious Word/Excel attachments or links—with look‑alike domains that spoof reputable security vendors such as ESET or Kaspersky to lull recipients into downloading malware. The attacker routinely compresses its payloads inside RAR or ZIP archives, embeds malicious DLLs, and leverages living‑off‑the‑land tools like Empire and Rclone for post‑exploitation activities. WIRTE also employs obfuscated command lines (XOR‑encrypted strings) and leverages native Windows APIs to execute malicious components without raising immediate suspicion. The group’s recent operational shift includes the deployment of a modular .NET suite dubbed AshTag, which provides data exfiltration, command execution, and in‑memory DLL loading capabilities. In early 2025 WIRTE further extended its operations into wiper malware aimed at Israeli targets, signaling an escalation from purely espionage to active disruption. The actor remains persistent even amid the Israel–Hamas conflict, suggesting a resilient infrastructure that can withstand regional countermeasures and continues to expand its victim scope over time.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
WIRTE, a Hamas‑affiliated sub‑group of the Gaza Cybergang, has been targeting governmental, financial, military and other critical sectors across the Middle East, North Africa and Europe since at least August 2018. The actor employs spearphishing with look‑alike domains, compressed Office document payloads and living‑off‑the‑land tools to exfiltrate data, while recently expanding into wiper attacks against Israeli organisations. Despite fluctuating geopolitical tensions, WIRTE remains operational, adaptively extending its toolset and victimology.
Goals & Targeting
WIRTE’s strategic objectives centre on geopolitical intelligence gathering for Hamas and affiliated actors, prioritising high‑value information from state entities, defence establishments, and industrial sectors. By infiltrating diplomatic missions, financial institutions and critical infrastructure across a broad geographic footprint—including the US, EU countries, Australia and East Asia—the group seeks to collect insights that could influence regional power dynamics, secure strategic resources, or support military planning. The inclusion of wiper attacks targets political deterrence and signal escalation rather than purely data theft, indicating a dual‑purpose campaign that blends espionage with active disruption.
Enhanced Description
Key Capabilities
No campaigns linked yet.
No observed data linked yet.
42
Techniques
51
Tools
0
Campaigns
40
IOCs
0
Observed Data
7
Tactics