WIRTE

MITRE ATT&CK: G0090 View on attack.mitre.org

Aliases: Ashen Lepus, WIRTE

First seen
2018-08-01 00:00:00
Origin
PS
Primary motivation
espionage
Sophistication
intermediate
Resource level
organization
Actor type
nation-state
Related IoCs
17 (17 malicious)
Last IoC activity
2026-07-13 01:41:13
Profile updated
2026-07-07 12:08:20

Targeted industries: defense-and-aerospace financial-services government-and-public-sector professional-services technology-and-telecommunications

Targeted regions: country_code:ps country_code:il country_code:eg country_code:sy country_code:sa country_code:jo country_code:lb country_code:iq

Context

WIRTE is a cyberespionage actor, believed to be a subgroup of the Hamas-affiliated Gaza Cybergang, that has been active since at least August 2018. WIRTE has targeted diplomatic, financial, military, legal, and technology organizations across the Middle East, North Africa, and in Europe to gather intelligence. WIRTE has remained persistently active despite the ongoing Israel-Hamas conflict and has expanded their operations to include wiper malware attacks against Israeli targets.

Recent IoC activity

17 malicious indicators in Maltiverse are attributed to WIRTE (G0090). The 17 most recently updated:

TypeIndicatorUpdatedSources
file sample 6bd3d05aef89cd03d6b49b20716775fe92f0cf8a3c2747094404ef98f96e9376 2026-07-13 2
file sample 739a5199add1d970ba22d69cc10b4c3a13b72136be6d45212429e8f0969af3dc 2026-04-05 2
file sample f9816bc81de2e8639482c877a8defcaed9b15ffdce12beaef1cff3fea95999d4 2026-03-03 1
file sample f554c43707f5d87625a3834116a2d22f551b1d9a5aff1e446d24893975c431bc 2026-03-03 1
file sample ebe3b6977f66be30a22c2aff9b50fec8529dfa46415ea489bd7961552868f6b5 2026-03-03 1
file sample e71a292eafe0ca202f646af7027c17faaa969177818caf08569bd77838e93064 2026-03-03 1
file sample b00491dc178a3d4f320951bccb17eb85bfef23e718b4b94eb597c90b5b6e0ba2 2026-03-03 1
file sample a17858f40ff506d59b5ee1ba2579da1685345206f2c7d78cb2c9c578a0c4402b 2026-03-03 1
file sample 8c44fa9bf68341c61ccaca0a3723945543e2a04d9db712ae50861e3fa6d9cc98 2026-03-03 1
file sample 8870bd358d605a5685a5f9f7785b5fee5aebdcb20e4e62153623f764d7366a3c 2026-03-03 1
file sample 7e5769cd8128033fc933fbf3346fe2eb9c8e9fc6aa683546e9573e7aa01a8b6b 2026-03-03 1
file sample 66ab29d2d62548faeaeadaad9dd62818163175872703fda328bb1b4894f5e69e 2026-03-03 1
file sample 4e1f7b48249dd5bf3a857d5d017f0b88c0372749fa156f5456056767c5548345 2026-03-03 1
file sample 3502c9e4896802f069ef9dcdba2a7476e1208ece3cd5ced9f1c4fd32d4d0d768 2026-03-03 1
file sample 30490ba95c42cefcca1d0328ea740e61c26eaf606a98f68d26c4a519ce918c99 2026-03-03 1
file sample 2d71d7e6ffecab8eefa2d6a885bcefe639fca988bdcac99e9b057e61698a1fd6 2026-03-03 1
file sample 1f3bd755de24e00af2dba61f938637d1cc0fbfd6166dba014e665033ad4445c0 2026-03-03 1

Detection coverage

  • 13 YARA rules
  • 551 Sigma rules

Malware & tools used

  • Visual Basic (attack-pattern)
  • Local Email Collection (attack-pattern)
  • Malicious File (attack-pattern)
  • Upload Malware (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Malicious Link (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Tool (attack-pattern)
  • Email Accounts (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Domains (attack-pattern)
  • Web Protocols (attack-pattern)
  • DLL (attack-pattern)
  • System Checks (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Impersonation (attack-pattern)
  • Native API (attack-pattern)
  • Regsvr32 (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Compression (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • PowerShell (attack-pattern)

Reports & references

  • Kaspersky — 105044 (report)
  • lab52.io — Wirte Group Attacking The Middle East (report)
  • Palo Alto Unit 42 — Hamas Affiliate Ashen Lepus Uses New Malware Suite Ashtag (report)
  • MITRE ATT&CK — G0090 (report)
  • research.checkpoint.com — Hamas Affiliated Threat Actor Expands To Disruptive Activity (report)

External references