WIRTE
MITRE ATT&CK: G0090 View on attack.mitre.org
Aliases: Ashen Lepus, WIRTE
- First seen
- 2018-08-01 00:00:00
- Origin
- PS
- Primary motivation
- espionage
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- nation-state
- Related IoCs
- 17 (17 malicious)
- Last IoC activity
- 2026-07-13 01:41:13
- Profile updated
- 2026-07-07 12:08:20
Targeted industries: defense-and-aerospace financial-services government-and-public-sector professional-services technology-and-telecommunications
Targeted regions: country_code:ps country_code:il country_code:eg country_code:sy country_code:sa country_code:jo country_code:lb country_code:iq
Context
WIRTE is a cyberespionage actor, believed to be a subgroup of the Hamas-affiliated Gaza Cybergang, that has been active since at least August 2018. WIRTE has targeted diplomatic, financial, military, legal, and technology organizations across the Middle East, North Africa, and in Europe to gather intelligence. WIRTE has remained persistently active despite the ongoing Israel-Hamas conflict and has expanded their operations to include wiper malware attacks against Israeli targets.
Recent IoC activity
17 malicious indicators in Maltiverse are attributed to WIRTE (G0090). The 17 most recently updated:
Detection coverage
- 13 YARA rules
- 551 Sigma rules
Malware & tools used
- Visual Basic (attack-pattern)
- Local Email Collection (attack-pattern)
- Malicious File (attack-pattern)
- Upload Malware (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Windows Command Shell (attack-pattern)
- Malicious Link (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Local Data Staging (attack-pattern)
- Tool (attack-pattern)
- Email Accounts (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Domains (attack-pattern)
- Web Protocols (attack-pattern)
- DLL (attack-pattern)
- System Checks (attack-pattern)
- Spearphishing Link (attack-pattern)
- Impersonation (attack-pattern)
- Native API (attack-pattern)
- Regsvr32 (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Compression (attack-pattern)
- Command Obfuscation (attack-pattern)
- PowerShell (attack-pattern)
Reports & references
- Kaspersky — 105044 (report)
- lab52.io — Wirte Group Attacking The Middle East (report)
- Palo Alto Unit 42 — Hamas Affiliate Ashen Lepus Uses New Malware Suite Ashtag (report)
- MITRE ATT&CK — G0090 (report)
- research.checkpoint.com — Hamas Affiliated Threat Actor Expands To Disruptive Activity (report)