AshTag

S9031

Malware.View on attack.mitre.org

About this malware

AshTag is a modular .NET backdoor with multiple features that has been used by WIRTE since at least 2025. AshTag is designed for persistence and remote command execution and can masquerade as a legitimate VisualServer utility.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

The AshTag AshenOrchestrator component payload as been Base64 encoded and embedded with HTML content from the C2 server.

T1036.005
Match Legitimate Resource Name or Location

AshTag has masqueraded as a legitimate VisualServer utility.

T1041
Exfiltration Over C2 Channel

AshTag has exfiltrated reconnaissance data on targeted systems to C2 servers.

T1047
Windows Management Instrumentation

AshTag can use a .NET program to execute WMI queries and send unique victim IDs to C2.

T1053.005
Scheduled Task

AshTag can set persistence using scheduled tasks.

T1057
Process Discovery

The AshTag AshenOrchestrator component has process management functionality.

T1059.007
JavaScript

AshTag can use JSON files to deliver payloads and configuration files.

T1071.001
Web Protocols

AshTag can use HTTP to send and receive data from C2.

T1082
System Information Discovery

The AshTag loader and AshenOrchestrator components can collect reconnaissance data from victim machines.

T1083
File and Directory Discovery

The AshTag AshenOrchestrator component can enumerate files on victim hosts.

T1102
Web Service

AshTag can download malicious payloads from file sharing services.

T1105
Ingress Tool Transfer

The AshTag stager component can retrieve and execute the main payload.

T1113
Screen Capture

The AshTag AshenOrchestrator component has the ability to take screenshots.

T1140
Deobfuscate/Decode Files or Information

The AshTag stager compoment can decode and decrypt Base64 and XOR-encrypted payloads.

T1204.002
Malicious File

AshTag has been executed through victims downloading and opening malicious RAR archive files.

View all 19 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Palo Alto Ashen Lepus DEC 2025 Open source
    Unit 42. (2025, December 11). Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite. Retrieved April 20, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.