Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Ashen Lepus, network, software application, tracked as, a pen name, NosyDoor, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, a botnet, root access

Description

WIRTE is a state‑aligned cyberespionage actor believed to operate as part of the Hamas‑affiliated Gaza Cybergang. Since August 2018 it has carried out sophisticated social engineering campaigns against diplomatic, financial, military, legal, technology and critical‑infrastructure entities across the Middle East, North Africa and Europe. The group’s tactics blend classic spearphishing—using compromised email accounts and malicious Word/Excel attachments or links—with look‑alike domains that spoof reputable security vendors such as ESET or Kaspersky to lull recipients into downloading malware. The attacker routinely compresses its payloads inside RAR or ZIP archives, embeds malicious DLLs, and leverages living‑off‑the‑land tools like Empire and Rclone for post‑exploitation activities. WIRTE also employs obfuscated command lines (XOR‑encrypted strings) and leverages native Windows APIs to execute malicious components without raising immediate suspicion. The group’s recent operational shift includes the deployment of a modular .NET suite dubbed AshTag, which provides data exfiltration, command execution, and in‑memory DLL loading capabilities. In early 2025 WIRTE further extended its operations into wiper malware aimed at Israeli targets, signaling an escalation from purely espionage to active disruption. The actor remains persistent even amid the Israel–Hamas conflict, suggesting a resilient infrastructure that can withstand regional countermeasures and continues to expand its victim scope over time.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Healthcare
Manufacturing
Education
Energy
Critical infrastructure
Non profit
Media
Pharmaceutical
Aviation
Hospitality
Aerospace
Retail
Information technology
Think tank
Transportation
Mining
Chemical
Gaming
Legal services
Utilities
Nuclear
Entertainment
Oil gas
Maritime
Food agriculture
Construction

Targeted Countries / Regions

CN
US
RU
IR
IL
JP
VN
GB
AU
SA
PK
TW
AE
UA
CA
TR
SG
KR
IN
DE
BY
MX
ES
PL
EG
RO
FR
NG
KP
IT
LB
AZ
KZ

AI Analysis

Grounded in web research
· 2 days ago

Executive Summary

WIRTE, a Hamas‑affiliated sub‑group of the Gaza Cybergang, has been targeting governmental, financial, military and other critical sectors across the Middle East, North Africa and Europe since at least August 2018. The actor employs spearphishing with look‑alike domains, compressed Office document payloads and living‑off‑the‑land tools to exfiltrate data, while recently expanding into wiper attacks against Israeli organisations. Despite fluctuating geopolitical tensions, WIRTE remains operational, adaptively extending its toolset and victimology.

Goals & Targeting

WIRTE’s strategic objectives centre on geopolitical intelligence gathering for Hamas and affiliated actors, prioritising high‑value information from state entities, defence establishments, and industrial sectors. By infiltrating diplomatic missions, financial institutions and critical infrastructure across a broad geographic footprint—including the US, EU countries, Australia and East Asia—the group seeks to collect insights that could influence regional power dynamics, secure strategic resources, or support military planning. The inclusion of wiper attacks targets political deterrence and signal escalation rather than purely data theft, indicating a dual‑purpose campaign that blends espionage with active disruption.

Enhanced Description

Key Capabilities

  • Spearphishing attachments and links crafted through compromised email accounts
  • Use of look‑alike domains mimicking trusted security vendors to distribute malware
  • Compression of malicious payloads into RAR/ZIP archives with DLL sideloading
  • Living‑off‑the‑land exploitation via tools such as Empire and Rclone
  • Command‑line obfuscation using XORed strings and native API calls
  • Dynamic domain acquisition and C2 configuration that checks user‑agent/location to avoid sandbox environments
  • Data staging on local devices prior to exfiltration
  • Wiper malware deployment against targeted organisations
  • Defence‑evasion through sandbox detection and masquerading techniques

ATT&CK Techniques

Execution
8 techniques
Resource Development
8 techniques
Stealth
14 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. Check Point Wirte NOV 2024 — Check Point. (2024, November 12). Hamas-affiliated Threat Actor WIRTE Continues its Middle East Operations and Moves to Disruptive Activity. Retrieved April 20, 2026.
  2. Lab52 WIRTE Apr 2019 — S2 Grupo. (2019, April 2). WIRTE Group attacking the Middle East. Retrieved May 24, 2019.
  3. Palo Alto Ashen Lepus DEC 2025 — Unit 42. (2025, December 11). Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite. Retrieved April 20, 2026.
  4. Kaspersky WIRTE November 2021 — Yamout, M. (2021, November 29). WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019. Retrieved February 1, 2022.
  5. www.malwarebytes.com — Cited by web research for: network
  6. blog.talosintelligence.com — Cited by web research for: NosyDoor
  7. attack.mitre.org — Cited by web research for: Sandworm Team
  8. attack.mitre.org — Cited by web research for: T1583
  9. www.group-ib.com — Cited by web research for: Phoenix

Intel Summary

42

Techniques

51

Tools

0

Campaigns

40

IOCs

0

Observed Data

7

Tactics

Tags

APT
Government Targeting
Wiper / Destructive
cyberespionage
wiper_malware
Middle_East
Hamas_affiliated

Details

MITRE ID
G0090
Type
Unknown
Primary Motivation
Espionage
Country of Origin
P
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--f8cb7b36-62ef-4488-8a6d-a7033e3271c1
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.