◇ SIGN IN
← all actors
apt

WIRTE

activemedium confidence
APT / State-sponsored
Ashen LepusGaza Cybergang subgroup
Attribution
Palestinian — assessed Hamas-affiliated (Gaza Cybergang subgroup)
Origin
Palestinian Territories
First seen
2018
Last active
2025
Motivation
Espionage
Confidence
medium
MENA targeting
Palestinian Authority, Jordan, Iraq, Egypt, Saudi Arabia (per Check Point's specific victim list); Lebanon, Syria, Turkey, Armenia, Cyprus (per Securelist's broader campaign list)
Sectors
Diplomatic, financial, military, legal, technology, government
MITRE ATT&CK
Why it mattersState-sponsored / APT actor, medium confidence, documented targeting Palestinian Authority, Jordan, Iraq (Diplomatic, financial, military sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

WIRTE is a Hamas-affiliated Gaza Cybergang subgroup active since 2018, conducting espionage against government, diplomatic, and military targets across the Middle East and North Africa, and — since 2024 — expanding into disruptive wiper attacks against Israel.

History

WIRTE has been active since at least August 2018 and is assessed to be a subgroup of the Hamas-affiliated Gaza Cybergang. Kaspersky, Check Point, and Palo Alto Unit 42 (which tracks the cluster as Ashen Lepus) have documented its evolution from a stealthy espionage actor into one that also conducts destructive operations.

The group favors low-profile tradecraft: politically themed decoy documents, VBS/PowerShell loaders, DLL side-loading (e.g., the AshenLoader technique), and modular backdoors such as its custom implants and the AshTag malware suite. This emphasis on living-off-the-land delivery and side-loading has helped WIRTE persist despite intense scrutiny during the Israel-Hamas conflict.

MENA is WIRTE's sole theater. Espionage targeting spans the Palestinian Authority, Jordan, Iraq, Egypt, and Saudi Arabia, with documented expansion to Oman and Morocco, concentrated in diplomatic, financial, military, legal, and technology organizations. In 2024 the group added a destructive dimension, deploying the SameCoin wiper against Israeli entities in two waves (February and October 2024) — the October wave impersonating an Israeli ESET reseller to hit hospitals and municipalities with propaganda-laden payloads.

WIRTE remained active into late 2025. Unit 42 reported the Ashen Lepus cluster continuing operations even after the October 2025 Gaza ceasefire, deploying the newly discovered AshTag malware suite and AshenLoader sideloading against over a dozen Middle Eastern government and diplomatic organizations, with hands-on-keyboard activity inside victim environments.

Notable campaigns

2021
WIRTE Middle East espionage
Kaspersky-documented VBS-based espionage against government and diplomatic targets across the region.
2024
SameCoin wiper waves
Destructive wiper attacks against Israeli hospitals and municipalities, including impersonation of an ESET reseller.
2025
Ashen Lepus / AshTag suite
Post-ceasefire espionage against Middle Eastern government and diplomatic entities using AshenLoader sideloading and the AshTag backdoor suite.