- Target Sectors
- Diplomatic, Financial, Military, Legal, Technology, Government
- Associated Malware
- LitePower, Ferocious, SurveyScript, AshTag, AshenLoader, AshStager, IronWind, SameCoin
Overview
WIRTE, also tracked under the alias Ashen Lepus (G0090), is a sophisticated cyber espionage actor that has been actively conducting operations since at least August 2018. The group is widely believed to be a subgroup within the Hamas-affiliated Gaza Cybergang ecosystem, functioning as its highly active intelligence-gathering arm. While there have been instances of misattribution associating WIRTE with Iranian state-sponsored activity, current intelligence definitively links their tradecraft and objectives to Palestinian political goals.
WIRTE’s primary motivation centers around regional espionage, focusing on the collection of sensitive intelligence related to national defense, external relations, and internal political developments across Middle Eastern states. They aim to provide actionable strategic intelligence to their affiliates. The group’s typical targets include diplomatic, financial, military, legal, and technology organizations, initially primarily within the Middle East and North Africa, with some reported activity in Europe. Recent intelligence indicates an expansion of their operational scope to include entities in Oman and Morocco, alongside persistent targeting of the Palestinian Authority, Jordan, and Egypt. Notably, WIRTE has evolved beyond pure espionage, integrating disruptive wiper malware attacks against Israeli targets into their operations. This strategic shift highlights a growing willingness to engage in more impactful cyber activity in alignment with regional conflicts.
Tactics & Techniques
WIRTE employs a blend of established and evolving tactics, techniques, and procedures (TTPs) to achieve its objectives, often leveraging common tools and subtle evasion methods to maintain a low profile.
Initial access is frequently gained through spear-phishing campaigns, where targets receive emails containing malicious Microsoft Word or Excel documents. These documents often incorporate geopolitical lure themes relevant to the Middle East. The group has been observed using Microsoft Excel droppers that utilize hidden spreadsheets and VBA or Excel 4.0 macros to deliver initial implants. Malicious links directing victims to malware downloads are another common vector. WIRTE has also exploited compromised email accounts, including one belonging to an Israel-based technology reseller, to disseminate their targeted spear-phishing messages, increasing their legitimacy in the eyes of potential victims.
For execution and persistence, WIRTE extensively uses scripting languages and living-off-the-land binaries. PowerShell scripts, such as their custom LitePower backdoor, are a staple for executing remote commands, downloading subsequent payloads, and gathering system information. They also leverage the Windows command line to open documents and VBScript in their infection chains. More sophisticated techniques include DLL side-loading, where legitimate executables are used to load malicious DLLs (e.g., AshenLoader delivering AshStager), and in-memory execution to reduce forensic artifacts. Persistence mechanisms include COM hijacking, notably observed with their Ferocious dropper, designed to maintain a foothold on compromised systems.
Defense evasion is a core aspect of WIRTE’s tradecraft. They rely on obfuscated PowerShell code and the abuse of legitimate tools like Microsoft Office macros, PowerShell, and various cloud services to blend in with normal network activity and avoid detection. Their command and control (C2) infrastructure often incorporates legitimate subdomains and is configured to check for user-agent strings and geographical location, preventing payloads from being delivered to sandboxed analysis environments. They also employ payload encryption and XOR encryption for command line strings to further conceal their malicious operations.
Credential access involves the collection of user credentials, often achieved by leveraging PowerShell scripts and Windows Management Instrumentation (WMI) queries to escalate privileges. For discovery, WIRTE utilizes reconnaissance tools like SurveyScript to map network topology and gather system metadata. Exfiltration of collected data typically occurs to their C2 infrastructure and has been observed using legitimate tools such as Rclone to transfer data to attacker-controlled servers, further masking malicious activity.
Their C2 communications primarily use HTTP and HTTPS over ports 2083 and 2087. A distinct feature of their C2 is that servers only respond to specific user agents unique to each sample, redirecting to legitimate websites for unrecognized requests, a technique designed to thwart analysis. Next-stage payloads are often discreetly embedded within HTML tags.
Notable Campaigns
WIRTE has a consistent operational tempo, with several notable campaigns and incidents highlighting their evolving capabilities and strategic shifts.
The group has been continuously active since at least 2018, demonstrating a sustained commitment to intelligence gathering. In November 2023, Check Point Research observed a campaign by WIRTE that utilized custom loaders like IronWind. This campaign targeted entities across the Middle East, specifically in the Palestinian Authority, Jordan, Egypt, and Saudi Arabia.
A significant shift in WIRTE’s operations was observed in 2024, when the group expanded beyond pure espionage to conduct disruptive attacks. They were linked to at least two waves of wiper malware attacks against Israeli entities in February and October 2024, employing a custom wiper malware known as SameCoin. This marked a notable expansion of their objectives to include direct impact operations.
Most recently, in December 2025, Palo Alto Networks Unit 42 detailed an evolving espionage campaign attributed to Ashen Lepus (WIRTE). This campaign introduced a new, fully featured, modular .NET malware suite dubbed AshTag. The infection chain for AshTag typically begins with social engineering, using decoy PDFs and RAR archives, and relies on DLL side-loading performed by the custom AshenLoader malware, which then delivers the AshStager DLL payload to execute the main malware in memory. This campaign not only continued WIRTE’s focus on Middle Eastern governmental and diplomatic entities but also expanded its geographic reach to include Oman and Morocco.
Associated Malware & Tools
WIRTE relies on a combination of custom-developed malware, bespoke tools, and the abuse of legitimate software.
Their custom malware includes:
- LitePower: A lightweight, PowerShell-based backdoor. It provides WIRTE with capabilities for remote command execution, downloading additional payloads, and conducting system reconnaissance.
- Ferocious: A modular implant designed for persistence on compromised systems and capable of data exfiltration, often deployed as a “Ferocious Dropper”.
- SurveyScript: A reconnaissance tool used to collect system metadata and map out network topologies of targeted environments.
- AshTag: A more recent, fully featured, modular .NET malware suite first observed in late 2025. It is designed for robust data exfiltration, command execution, and executing additional modules in memory.
- AshenLoader and AshStager: Components of the AshTag malware suite. AshenLoader acts as a custom loader, initiating the infection, while AshStager is a DLL payload used for in-memory execution of the AshTag malware.
- IronWind: A custom loader utilized in campaigns identified in late 2023.
- SameCoin: A custom wiper malware used in disruptive attacks against Israeli targets in 2024, demonstrating WIRTE’s capacity for destructive operations.
In addition to their custom toolset, WIRTE frequently abuses legitimate tools and frameworks, including Microsoft Office macros, PowerShell, WMI, VBScript, and the Windows command line, as part of their “living off the land” approach. They have also been observed using the open-source file transfer utility Rclone for data exfiltration.
Current Status
WIRTE remains a highly active and persistent threat actor. Despite ongoing regional conflicts, particularly the Israel-Hamas conflict, the group has shown no signs of decreased activity; instead, it has continued to adapt and expand its operations.
Recent intelligence from late 2025 and early 2026 confirms their ongoing commitment to intelligence collection, evidenced by the development and deployment of new malware suites like AshTag. Their targeting has also broadened geographically, now including nations like Oman and Morocco, indicating a wider strategic interest beyond their historical focus.
WIRTE consistently refines its TTPs, evolving its toolkit and operational methodologies to evade detection and ensure continued access to sensitive information. The group’s expansion into wiper malware attacks further underscores its dynamic nature and willingness to escalate activities in response to geopolitical events. Security professionals should anticipate WIRTE to continue leveraging current events as lures and to persist in developing new and stealthy tools to achieve its cyber espionage and disruptive objectives across the Middle East and beyond.
Related content
Worried this actor targets your sector?
Let's map your exposure before they find it themselves.
Book an advisory call