Check Point. (2024, November 12). Hamas-affiliated Threat Actor WIRTE Continues its Middle East Operations and Moves to Disruptive Activity. Retrieved April 20, 2026.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
MalwareIronWind | IronWind has used Base64 encoding and XOR encryption with the key “53” to obfuscate command strings. |
| T1027.010 Command Obfuscation |
GroupWIRTE | WIRTE has XOR encrypted command line strings to conceal malware execution chains. |
| T1027.010 Command Obfuscation |
MalwareHavoc | Havoc has utilized XOR encryption with the key “01-01-1900” to obfuscate command strings. |
| T1027.015 Compression |
GroupWIRTE | WIRTE has compressed malicious files within RAR and ZIP archives for obfuscation. |
| T1033 System Owner/User Discovery |
MalwareIronWind | IronWind can enumerate the username on victim's systems. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupWIRTE | WIRTE has used security service provider naming conventions such as ESET and Kasperky ("Kaspersky Update Agent") in order to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSameCoin | SameCoin has named files to appear legitimate such as "MicrosoftEdge.exe." |
| T1053.005 Scheduled Task |
MalwareSameCoin | SameCoin has the ability to set a scheduled task for execution. |
| T1059.003 Windows Command Shell |
GroupWIRTE | WIRTE has used the Windows command line as part of infection chains to open documents. |
| T1059.003 Windows Command Shell |
MalwareIronWind | IronWind has used the Windows command shell to execute malicious files. |
| T1070 Indicator Removal |
MalwareIronWind | IronWind has used a .NET DLL named "exit-DN4-core.dll" to terminate malicious processes running on victim's systems. |
| T1071.001 Web Protocols |
MalwareIronWind | IronWind can used HTTP to send information to C2 about the targeted system. |
| T1082 System Information Discovery |
MalwareIronWind | IronWind can capture the OS version and computer name of the compromised host. |
| T1083 File and Directory Discovery |
MalwareSameCoin | SameCoin can list all system files and can avoid wiping specific directories such as Program Files, Windows, and Users. |
| T1106 Native API |
GroupWIRTE | WIRTE has used the `RtlIpv4StringToAddressA` to convert IP-formatted string to a byte array. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareIronWind | IronWind can deobfuscate the next stage payload using Base64 and XOR operations with the key "53". |
| T1204.001 Malicious Link |
GroupWIRTE | WIRTE has used links embedded in emails to lure users into downloading malicious files. |
| T1204.002 Malicious File |
MalwareHavoc | Havoc has been executed by victims through the use of targeted lures and crafted decoy documents. |
| T1204.002 Malicious File |
GroupWIRTE | WIRTE has attempted to lure users into opening malicious documents including MS Word and Excel files, at times using a decoy document to encourage execution of malicious payloads. |
| T1485 Data Destruction |
MalwareSameCoin | SameCoin can overwrite designated files on targeted systems with random bytes. |
| T1491.001 Internal Defacement |
MalwareSameCoin | SameCoin can alter the victim’s background to display an image showing the name of Hamas’s military wing. |
| T1518 Software Discovery |
MalwareIronWind | IronWind can list installed software on targeted hosts. |
| T1534 Internal Spearphishing |
MalwareSameCoin | SameCoin can send its Setup.exe file as an attachment to other addresses in the same compromised organization. |
| T1566.002 Spearphishing Link |
GroupWIRTE | WIRTE has sent targeted spearphishing emails with malicious links directing victims to malware downloads. |
| T1570 Lateral Tool Transfer |
MalwareSameCoin | SameCoin can copy its wiper executable to remote machines within the same Active Directory. |
| T1574.001 DLL |
MalwareIronWind | IronWind has used DLL sideloading for execution. |
| T1574.001 DLL |
MalwareHavoc | Havoc has leveraged legitimate executables to side-load malicious payloads. |
| T1574.001 DLL |
GroupWIRTE | WIRTE has used RAR archives containing a legitimate executable and a lure document to execute malicious DLLs via sideloading. |
| T1583.001 Domains |
GroupWIRTE | WIRTE has registered domains designed to mimic legitimate sites for use in phishing campaigns. |
| T1586.002 Email Accounts |
GroupWIRTE | WIRTE has used compromised emails, including one belonging to an Israel-based technology reseller, to deliver targeted spearphishing messages. |
| T1614 System Location Discovery |
MalwareSameCoin | SameCoin can attempt to connect to the Israel Home Front Command site, oref.org[.]il, which is only reachable from within Israel to verify the target's location. |
| T1679 Selective Exclusion |
MalwareSameCoin | SameCoin can avoid overwriting file names that contain “desktop.ini” and “conf.conf." |
| T1684.001 Impersonation |
GroupWIRTE | WIRTE has used utilized look-alike domains and graphics of trusted security solution providers to entice victims to click on phishing links. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.