WIRTE

G0090

Threat group.View on attack.mitre.org

About this group

WIRTE is a cyberespionage actor, believed to be a subgroup of the Hamas-affiliated Gaza Cybergang, that has been active since at least August 2018. WIRTE has targeted diplomatic, financial, military, legal, and technology organizations across the Middle East, North Africa, and in Europe to gather intelligence. WIRTE has remained persistently active despite the ongoing Israel-Hamas conflict and has expanded their operations to include wiper malware attacks against Israeli targets.

Techniques used26

Procedure examples26

TechniqueProcedure example
T1027.010
Command Obfuscation

WIRTE has XOR encrypted command line strings to conceal malware execution chains.

T1027.015
Compression

WIRTE has compressed malicious files within RAR and ZIP archives for obfuscation.

T1036.005
Match Legitimate Resource Name or Location

WIRTE has used security service provider naming conventions such as ESET and Kasperky ("Kaspersky Update Agent") in order to appear legitimate.

T1041
Exfiltration Over C2 Channel

WIRTE has exfiltrated collected victim data to C2 infrastructure.

T1059.001
PowerShell

WIRTE has used PowerShell for script execution.

T1059.003
Windows Command Shell

WIRTE has used the Windows command line as part of infection chains to open documents.

T1059.005
Visual Basic

WIRTE has used VBScript in its operations.

T1071.001
Web Protocols

WIRTE has used HTTP for network communication.

T1074.001
Local Data Staging

WIRTE has staged collected documents of interest in `C:\Users\Public folder`.

T1105
Ingress Tool Transfer

WIRTE has downloaded PowerShell code from the C2 server to be executed.

T1106
Native API

WIRTE has used the `RtlIpv4StringToAddressA` to convert IP-formatted string to a byte array.

T1114.001
Local Email Collection

WIRTE has collected documents from victims' email accounts.

T1140
Deobfuscate/Decode Files or Information

WIRTE has used Base64 to decode malicious VBS script.

T1204.001
Malicious Link

WIRTE has used links embedded in emails to lure users into downloading malicious files.

T1204.002
Malicious File

WIRTE has attempted to lure users into opening malicious documents including MS Word and Excel files, at times using a decoy document to encourage execution of malicious payloads.

View all 26 procedure examples

Software8

Campaigns0

None recorded.

References4

  1. Check Point Wirte NOV 2024 Open source
    Check Point. (2024, November 12). Hamas-affiliated Threat Actor WIRTE Continues its Middle East Operations and Moves to Disruptive Activity. Retrieved April 20, 2026.
  2. Kaspersky WIRTE November 2021 Open source
    Yamout, M. (2021, November 29). WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019. Retrieved February 1, 2022.
  3. Lab52 WIRTE Apr 2019 Open source
    S2 Grupo. (2019, April 2). WIRTE Group attacking the Middle East. Retrieved May 24, 2019.
  4. Palo Alto Ashen Lepus DEC 2025 Open source
    Unit 42. (2025, December 11). Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite. Retrieved April 20, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.