RaqibCTI
malware

AshTag

S9031 · ATT&CK v19.2
Platforms
Windows
Tracked actors
1

View on attack.mitre.org ↗

Description

[AshTag](https://attack.mitre.org/software/S9031) is a modular .NET backdoor with multiple features that has been used by [WIRTE](https://attack.mitre.org/groups/G0090) since at least 2025. [AshTag](https://attack.mitre.org/software/S9031) is designed for persistence and remote command execution and can masquerade as a legitimate VisualServer utility.(Citation: Palo Alto Ashen Lepus DEC 2025)

Actors that use this

1 tracked actor
WIRTEATT&CK-attributed