WIRTE
Also known as: Ashen Lepus
Overview
WIRTE is a cyberespionage actor, believed to be a subgroup of the Hamas-affiliated Gaza Cybergang, that has been active since at least August 2018. WIRTE has targeted diplomatic, financial, military, legal, and technology organizations across the Middle East, North Africa, and in Europe to gather intelligence. WIRTE has remained persistently active despite the ongoing Israel-Hamas conflict and has expanded their operations to include wiper malware attacks against Israeli targets.
Naming & attribution
WIRTE is tracked under 2 names across the industry. It uses 26 documented ATT&CK techniques — more than 60% of the 174 groups tracked here.
| Name | First reported by |
|---|---|
| Ashen Lepus | Unit 42 |
| WIRTE | S2 Grupo |
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- TA505 — 15 shared techniques (33% overlap)
- APT-C-36 — 15 shared techniques (31% overlap)
- LazyScripter — 11 shared techniques (31% overlap)
- TA2541 — 12 shared techniques (29% overlap)
- Sidewinder India — 12 shared techniques (27% overlap)
- Storm-1811 — 12 shared techniques (27% overlap)
Malware families with current indicators
One family attributed to WIRTE, carrying 748 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- Havoc 748 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Capabilities
- Custom malware/implant development — ATT&CK: 6 attributed custom malware families
TTPs — 26 techniques across 7 tactics
Resource Development
-
T1583.001Domains -
T1586.002Email Accounts -
T1588.002Tool -
T1608.001Upload Malware
Initial Access
-
T1566.001Spearphishing Attachment -
T1566.002Spearphishing Link
Execution
-
T1059.001PowerShell -
T1059.003Windows Command Shell -
T1059.005Visual Basic -
T1106Native API -
T1204.001Malicious Link -
T1204.002Malicious File
Stealth
-
T1027.010Command Obfuscation -
T1027.015Compression -
T1036.005Match Legitimate Resource Name or Location -
T1140Deobfuscate/Decode Files or Information -
T1218.010Regsvr32 -
T1497.001System Checks -
T1574.001DLL -
T1684.001Impersonation
Collection
-
T1074.001Local Data Staging -
T1114.001Local Email Collection
Command and Control
-
T1071.001Web Protocols -
T1105Ingress Tool Transfer -
T1571Non-Standard Port
Exfiltration
Tools & malware (8)
LitePower · SameCoin · Ferocious · Empire · IronWind · Rclone · Havoc · AshTag
Reporting (3)
- Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite — Unit 42
- Hamas-affiliated Threat Actor WIRTE Continues its Middle East Operations and Moves to Disruptive Activity — Check Point
- WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019 — Yamout, M