IronWind

S9029

Malware.View on attack.mitre.org

About this malware

IronWind is a custom loader malware that has been in use since at least 2023 by actors including WIRTE to target entities in the Middle East.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1027.010
Command Obfuscation

IronWind has used Base64 encoding and XOR encryption with the key “53” to obfuscate command strings.

T1033
System Owner/User Discovery

IronWind can enumerate the username on victim's systems.

T1059.003
Windows Command Shell

IronWind has used the Windows command shell to execute malicious files.

T1070
Indicator Removal

IronWind has used a .NET DLL named "exit-DN4-core.dll" to terminate malicious processes running on victim's systems.

T1071.001
Web Protocols

IronWind can used HTTP to send information to C2 about the targeted system.

T1082
System Information Discovery

IronWind can capture the OS version and computer name of the compromised host.

T1140
Deobfuscate/Decode Files or Information

IronWind can deobfuscate the next stage payload using Base64 and XOR operations with the key "53".

T1518
Software Discovery

IronWind can list installed software on targeted hosts.

T1574.001
DLL

IronWind has used DLL sideloading for execution.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Check Point Wirte NOV 2024 Open source
    Check Point. (2024, November 12). Hamas-affiliated Threat Actor WIRTE Continues its Middle East Operations and Moves to Disruptive Activity. Retrieved April 20, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.