[WIRTE](https://attack.mitre.org/groups/G0090) has staged collected documents of interest in `C:\Users\Public folder`.(Citation: Palo Alto Ashen Lepus DEC 2025)
[WIRTE](https://attack.mitre.org/groups/G0090) has used the `RtlIpv4StringToAddressA` to convert IP-formatted string to a byte array.(Citation: Check Point Wirte NOV 2024)
Useful?
Typed relationships
Curated links to related activity — not this actor's alias list. Claimed personas are marked unverified; overlap / subgroup edges describe a related but distinct cluster, never the same actor.
Related cluster — overlap, not the same actor
Gaza Cybergang / Moleratsmedium confidencesource ↗WIRTE shows tooling/targeting overlap with the Molerats / Gaza Cybergang cluster (Proofpoint), tracked as a related-cluster edge rather than a merge.
Subgroup of
Gaza Cyberganghigh confidencesource ↗WIRTE (G0090) is a distinct Hamas-affiliated cluster operating as a subgroup within the Gaza Cybergang umbrella; the umbrella actor entity is deferred, so the target is a label for now.
Related
Semantically related in the corpus — a discovery aid, not asserted attribution.
[WIRTE](https://attack.mitre.org/groups/G0090) has used the Windows command line as part of infection chains to open documents.(Citation: Check Point Wirte NOV 2024)
[WIRTE](https://attack.mitre.org/groups/G0090) has used links embedded in emails to lure users into downloading malicious files.(Citation: Check Point Wirte NOV 2024)
[WIRTE](https://attack.mitre.org/groups/G0090) has attempted to lure users into opening malicious documents including MS Word and Excel files, at times using a decoy document to encourage execution of malicious payloads.(Citation: Kaspersky WIRTE November 2021)(Citation: Check Point Wirte NOV 2024)(
[WIRTE](https://attack.mitre.org/groups/G0090) has sent emails to intended victims with malicious MS Word and Excel attachments.(Citation: Kaspersky WIRTE November 2021)
[WIRTE](https://attack.mitre.org/groups/G0090) has sent targeted spearphishing emails with malicious links directing victims to malware downloads.(Citation: Check Point Wirte NOV 2024)
[WIRTE](https://attack.mitre.org/groups/G0090) has used compromised emails, including one belonging to an Israel-based technology reseller, to deliver targeted spearphishing messages.(Citation: Check Point Wirte NOV 2024)
[WIRTE](https://attack.mitre.org/groups/G0090) has directed victims to malicious payloads staged on file sharing services.(Citation: Palo Alto Ashen Lepus DEC 2025)
[WIRTE](https://attack.mitre.org/groups/G0090) has registered domains designed to mimic legitimate sites for use in phishing campaigns.(Citation: Check Point Wirte NOV 2024)(Citation: Palo Alto Ashen Lepus DEC 2025)
[WIRTE](https://attack.mitre.org/groups/G0090) has obtained and used [Empire](https://attack.mitre.org/software/S0363) and [Rclone](https://attack.mitre.org/software/S1040) for post-exploitation activities.(Citation: Lab52 WIRTE Apr 2019)(Citation: Palo Alto Ashen Lepus DEC 2025)
[WIRTE](https://attack.mitre.org/groups/G0090) has XOR encrypted command line strings to conceal malware execution chains.(Citation: Check Point Wirte NOV 2024)
[WIRTE](https://attack.mitre.org/groups/G0090) has configured C2 servers to check location and user-agent strings for victim endpoints to prevent sending a payload to sandboxed environments.(Citation: Palo Alto Ashen Lepus DEC 2025)
[WIRTE](https://attack.mitre.org/groups/G0090) has used security service provider naming conventions such as ESET and Kasperky ("Kaspersky Update Agent") in order to appear legitimate.(Citation: Kaspersky WIRTE November 2021)(Citation: Check Point Wirte NOV 2024)
[WIRTE](https://attack.mitre.org/groups/G0090) has compressed malicious files within RAR and ZIP archives for obfuscation. (Citation: Check Point Wirte NOV 2024)(Citation: Palo Alto Ashen Lepus DEC 2025)
[WIRTE](https://attack.mitre.org/groups/G0090) has used utilized look-alike domains and graphics of trusted security solution providers to entice victims to click on phishing links.(Citation: Check Point Wirte NOV 2024)
[WIRTE](https://attack.mitre.org/groups/G0090) has used RAR archives containing a legitimate executable and a lure document to execute malicious DLLs via sideloading.(Citation: Check Point Wirte NOV 2024)
[WIRTE](https://attack.mitre.org/groups/G0090) has used `regsvr32.exe` to trigger the execution of a malicious script.(Citation: Lab52 WIRTE Apr 2019)
Associated software
8 linked · 8 ATT&CK-attributed, 0 curated
Malware and tools this actor is known to use. ATT&CK-attributed rows are MITRE's own software↔group relationships; curated rows fill the gap for MENA actors ATT&CK doesn't track — treat those as analyst assessment, not authoritative attribution.
ATT&CK-attributed · 8
Sourced from MITRE ATT&CK's own uses relationships for this group.
Regional co-occurrence is association, not prediction. These techniques appeared alongside WIRTE's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Adaptive Application Control IntegrationT1036partialAdaptive Application Control IntegrationT1036.005partialAdaptive Application Control IntegrationT1204partialAdaptive Application Control IntegrationT1204.002partialAdvanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001significantAdvanced Anti-Phishing T1566.002significantApp GovernanceT1566significantAdvanced Threat HuntingT1114significantAdvanced Threat HuntingT1566significantAdvanced Threat HuntingT1566.002significantDefender for Cloud AppsT1027.010partialDefender for Cloud AppsT1071
respond · 11 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001partialAdvanced Anti-Phishing T1566.002partialAutomated Investigation and ResponseT1114significantAutomated Investigation and ResponseT1204.001significantAutomated Investigation and ResponseT1204.002significantAutomated Investigation and ResponseT1566significantAutomated Investigation and ResponseT1566.001significantAutomated Investigation and ResponseT1566.002significantIncident ResponseT1059minimalIncident ResponseT1566minimalQuarantine PoliciesT1027significantQuarantine PoliciesT1036
Countermeasures · D3FEND
Defensive techniques that counter WIRTE's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.