WIRTE is a Hamas-affiliated Gaza Cybergang subgroup active since 2018, conducting espionage against government, diplomatic, and military targets across the Middle East and North Africa, and — since 2024 — expanding into disruptive wiper attacks against Israel.
WIRTE has been active since at least August 2018 and is assessed to be a subgroup of the Hamas-affiliated Gaza Cybergang. Kaspersky, Check Point, and Palo Alto Unit 42 (which tracks the cluster as Ashen Lepus) have documented its evolution from a stealthy espionage actor into one that also conducts destructive operations.
The group favors low-profile tradecraft: politically themed decoy documents, VBS/PowerShell loaders, DLL side-loading (e.g., the AshenLoader technique), and modular backdoors such as its custom implants and the AshTag malware suite. This emphasis on living-off-the-land delivery and side-loading has helped WIRTE persist despite intense scrutiny during the Israel-Hamas conflict.
MENA is WIRTE's sole theater. Espionage targeting spans the Palestinian Authority, Jordan, Iraq, Egypt, and Saudi Arabia, with documented expansion to Oman and Morocco, concentrated in diplomatic, financial, military, legal, and technology organizations. In 2024 the group added a destructive dimension, deploying the SameCoin wiper against Israeli entities in two waves (February and October 2024) — the October wave impersonating an Israeli ESET reseller to hit hospitals and municipalities with propaganda-laden payloads.
WIRTE remained active into late 2025. Unit 42 reported the Ashen Lepus cluster continuing operations even after the October 2025 Gaza ceasefire, deploying the newly discovered AshTag malware suite and AshenLoader sideloading against over a dozen Middle Eastern government and diplomatic organizations, with hands-on-keyboard activity inside victim environments.