Skip to main content

WIRTE

Repository Navigation

  • Actor workbench: WIRTE
  • TTP-to-detection matrix: all mapped techniques
  • Surface and capability routes: Endpoint RMM, Scripting, And User-Path Execution
  • Detection status: dashboard
  • Hunt workflow: hunt workflow
  • ATT&CK mappings: T1566 Phishing (M2); T1574.001 DLL Search Order Hijacking (M3); T1485 Data Destruction (M2); T1105 Ingress Tool Transfer (M3); T1567.002 Exfiltration to Cloud Storage (M3)
  • Mapped detections: DET-001 Intune Bulk Device Wipe Anomaly (Hunt, DRL-5); DET-004 Mail Click To Execution Correlation (Hunt, DRL-4)
  • Mapped hunts: HUNT-001 If identity-plane destructive tradecraft is attempted then privileged role activation or bulk device actions will appear in audit logs; HUNT-004 If VIP phishing is active then mail click events will correlate to risky sign-in or execution
  • IOC reference sources: SRC-CP-WIRTE-2024 Wiper references; trusted sender abuse; fake update artifacts; SRC-UNIT42-ASHTAG-2025 Malware hashes; domains; C2 paths; tool behavior
  • Tool detail pages: SameCoin; AshTag
  • Tool matrix: all actor-linked tools (2 mapped tool row(s))
  • Evidence records: EVD-010 / CLM-WIRTE-001
  • Imported research intakes: None currently mapped.
  • Intel update candidates: 1 current candidate(s)
  • Source IDs in structured data: SRC-CP-WIRTE-2024, SRC-UNIT42-ASHTAG-2025

Background

WIRTE is a Hamas-affiliated threat actor that Check Point Research has tracked since approximately 2018 across multiple operational phases. The group began as a conventional espionage cluster targeting Middle East government entities — Palestinian Authority institutions, Israeli government, Jordanian, Saudi, and Iraqi organizations — using phishing and commodity malware. Through 2022-2023, WIRTE operated primarily as a credential harvester and document stealer, consistent with an intelligence collection mandate.

The group's most significant operational shift occurred in October 2024, documented by Check Point Research: WIRTE expanded from espionage into disruptive and destructive activity against Israeli targets. The SameCoin wiper — a two-stage payload using a custom downloader and a wiper module — was deployed against Israeli financial institutions and hospital networks using fake security software update lures impersonating ESET, Kaspersky, and regional IT vendors. The timing and target selection (hospitals, financial sector) during active conflict suggest deliberate escalation toward civilian-impact sectors.

WIRTE's trusted-sender abuse technique is particularly concerning: the group has compromised legitimate government and regional organization email accounts to send phishing from email addresses with established trust histories, bypassing sender-reputation defenses. Combined with fake security software update themes, this creates a high-conversion delivery chain even for security-aware users.

Unit 42's October 2025 analysis of the AshTag backdoor documented continued WIRTE operations with updated Python-based tooling featuring modular architecture and encrypted C2. AshTag represents a maturation in custom capability development, suggesting WIRTE's technical sophistication is increasing alongside its operational ambition.

WIRTE and TA402 (Molerats) are both tracked as Hamas-affiliated and share Gaza Cybergang umbrella classifications in some vendor reporting. Analysts should treat them as potentially distinct subgroups unless source reporting explicitly clusters a specific campaign under both designations.

Aliases: Ashen Lepus; Gaza Cybergang-linked reporting.

Assessed sponsor: Hamas-affiliated in Check Point public reporting.

Relevance

WIRTE is high priority for Israeli public-sector defenders because Check Point reported expansion from espionage into disruptive activity against Israeli entities, including SameCoin-linked wiper activity.

Defensive Focus

  • Trusted sender abuse.
  • Fake security or vendor update lures.
  • Archive-to-execution chains.
  • DLL sideloading.
  • Wiper-preparation behavior.

Detection Ideas

  • Signed installer execution from archive or user download paths followed by same-directory DLL loads.
  • Inbound mail from trusted regional senders that suddenly includes archives, XLL/PPAM files, or update-themed links.
  • Fake ESET/Kaspersky/reseller update filenames.

Sources: SRC-CP-WIRTE-2024, SRC-PROOFPOINT-TA402-IRONWIND, SRC-UNIT42-ASHTAG-2025, SRC-S1-ISRAEL-HAMAS-CYBER-2023.

Public Reports

Primary vendor reporting:

  • Check Point Research, "WIRTE's Expanded Campaign Against Israel: From Espionage to Disruption" — October 2024. Documents the pivot to disruptive operations, SameCoin wiper deployment against Israeli financial and hospital sectors, trusted-sender-abuse technique, and fake security update lure themes. Source ID SRC-CP-WIRTE-2024.
  • Unit 42 / Palo Alto Networks, "AshTag: New Python-Based Backdoor in WIRTE Operations" — October 2025. Analysis of modular Python backdoor with encrypted C2, documenting continued WIRTE technical development. Source ID SRC-UNIT42-ASHTAG-2025.
  • SentinelLabs, "The Cyber Dimension of the Israel-Hamas Conflict" — 2023. Actor context for WIRTE within the Palestinian-affiliated threat landscape. Source ID SRC-S1-ISRAEL-HAMAS-CYBER-2023.
  • Proofpoint, TA402/IronWind reporting — Context for the broader Hamas-affiliated phishing ecosystem that overlaps with WIRTE's operational environment. Source ID SRC-PROOFPOINT-TA402-IRONWIND.
  • Arid Viper / APT-C-23 — Parallel Hamas-affiliated cluster with mobile-focused (Android malware) capability profile, operating alongside WIRTE's Windows-enterprise tradecraft within the same adversarial ecosystem.
  • TA402 — Hamas-affiliated phishing actor with overlapping operational environment; compare IronWind toolchain with WIRTE's SameCoin wiper and AshTag backdoor tradecraft.