Threat group.View on attack.mitre.org
WIRTE is a cyberespionage actor, believed to be a subgroup of the Hamas-affiliated Gaza Cybergang, that has been active since at least August 2018. WIRTE has targeted diplomatic, financial, military, legal, and technology organizations across the Middle East, North Africa, and in Europe to gather intelligence. WIRTE has remained persistently active despite the ongoing Israel-Hamas conflict and has expanded their operations to include wiper malware attacks against Israeli targets.
| Technique | Procedure example |
|---|---|
| T1027.010 Command Obfuscation |
WIRTE has XOR encrypted command line strings to conceal malware execution chains. |
| T1027.015 Compression |
WIRTE has compressed malicious files within RAR and ZIP archives for obfuscation. |
| T1036.005 Match Legitimate Resource Name or Location |
WIRTE has used security service provider naming conventions such as ESET and Kasperky ("Kaspersky Update Agent") in order to appear legitimate. |
| T1041 Exfiltration Over C2 Channel |
WIRTE has exfiltrated collected victim data to C2 infrastructure. |
| T1059.001 PowerShell |
WIRTE has used PowerShell for script execution. |
| T1059.003 Windows Command Shell |
WIRTE has used the Windows command line as part of infection chains to open documents. |
| T1059.005 Visual Basic |
WIRTE has used VBScript in its operations. |
| T1071.001 Web Protocols |
WIRTE has used HTTP for network communication. |
| T1074.001 Local Data Staging |
WIRTE has staged collected documents of interest in `C:\Users\Public folder`. |
| T1105 Ingress Tool Transfer |
WIRTE has downloaded PowerShell code from the C2 server to be executed. |
| T1106 Native API |
WIRTE has used the `RtlIpv4StringToAddressA` to convert IP-formatted string to a byte array. |
| T1114.001 Local Email Collection |
WIRTE has collected documents from victims' email accounts. |
| T1140 Deobfuscate/Decode Files or Information |
WIRTE has used Base64 to decode malicious VBS script. |
| T1204.001 Malicious Link |
WIRTE has used links embedded in emails to lure users into downloading malicious files. |
| T1204.002 Malicious File |
WIRTE has attempted to lure users into opening malicious documents including MS Word and Excel files, at times using a decoy document to encourage execution of malicious payloads. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.