Overview 90 indicators
WIRTE is a cyberespionage actor, believed to be a subgroup of the Hamas-affiliated Gaza Cybergang, that has been active since at least August 2018. WIRTE has targeted diplomatic, financial, military, legal, and technology organizations across the Middle East, North Africa, and in Europe to gather intelligence. WIRTE has remained persistently active despite the ongoing Israel-Hamas conflict and has expanded their operations to include wiper malware attacks against Israeli targets.
| domain | 82 | G0090-domain.txt |
| ipv4 | 6 | G0090.json |
| url | 1 | G0090.json |
| url_path | 1 | G0090.json |
Techniques 26 ATT&CK
Open in ATT&CK Navigator → or download the layer (26 techniques, layer 4.5)
- T1027.010 Command Obfuscation
- T1027.015 Compression
- T1036.005 Match Legitimate Resource Name or Location
- T1041 Exfiltration Over C2 Channel
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1071.001 Web Protocols
- T1074.001 Local Data Staging
- T1105 Ingress Tool Transfer
- T1106 Native API
- T1114.001 Local Email Collection
- T1140 Deobfuscate/Decode Files or Information
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1218.010 Regsvr32
- T1497.001 System Checks
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1571 Non-Standard Port
- T1574.001 DLL
- T1583.001 Domains
- T1586.002 Email Accounts
- T1588.002 Tool
- T1608.001 Upload Malware
- T1684.001 Impersonation
Software 8
Principal sources 28 reports
Ranked by how many of this actor's indicators each report brought in.
- 31x.com/k3yp0d/status/1857000802067345730
- 31research.checkpoint.com/2024/hamas-affiliated-threat-actor-expa…
- 23unit42.paloaltonetworks.com/hamas-affiliate-ashen-lepus-uses-new-ma…
- 23virustotal.com/gui/file/9979ed5993fb6d678727e6dacb15d2…
- 14twitter.com/malwrhunterteam/status/1233666708616941…
- 14twitter.com/SBousseaden/status/1222465015975948289
- 14app.any.run/tasks/b63ec8f5-70a6-4379-97e9-acbe3ce5e…
- 14app.any.run/tasks/4c404a75-4caf-430b-a901-c18bc8fb0…
Related groups 3
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 90 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
unit42.paloaltonetworks.com/hamas-affiliate-ashen-lepus-uses-new-ma… · virustotal.com/gui/file/9979ed5993fb6d678727e6dacb15d2…
account.techupinfo.com api.healthylifefeed.com api.medicinefinders.com api.softmatictech.com api.systemsync.info api.technology-system.com api.widetechno.info apiv2.onlinefieldtech.com auth.onlinefieldtech.com cdn.techpointinfo.com forum.technoforts.com forum.techtg.com healthylifefeed.com medicinefinders.com onlinefieldtech.com softmatictech.com status.techupinfo.com systemsync.info technoforts.com techpointinfo.com techtg.com techupinfo.com widetechno.info -
blog.talosintelligence.com/2018/02/targeted-attacks-in-middle-east… · twitter.com/SaudiDFIR/status/1119666633251930113 · twitter.com/James_inthe_box/status/1119932303088578… · twitter.com/MoBustami/status/1119959411156488192 · x.com/malwrhunterteam/status/1998743764630732… · virustotal.com/gui/file/d9dc90fd23cd2ad5e5a1b9df65d36f…
domain check.office365-update.com domain download.share2file.pro domain eg.foxlove.life domain fox.foxlove.life domain jo.foxlove.life domain update.share2file.pro ipv4 194.38.11.3:1790 -
x.com/k3yp0d/status/1857000802067345730 · research.checkpoint.com/2024/hamas-affiliated-threat-actor-expa…
bankjordan.com dentalaccord.com easybackupcloud.com economymentor.com economystocking.com egyptican.com egyptskytours.com egypttourism-online.com ellemedic.com finance-analyst.com financecovers.com financeinfoguide.com healthcarb.com healthoptionstoday.com healthscratches.com jordanrefugees.com jordansons.com king-pharmacy.com master-dental.com microsoftliveforums.com microsoftteams365.com microsoftwindowshelp.com printspoolerupdates.com qrdorks.com saudiarabianow.org saudiday.org suppertools.com support-api.financecovers.com theshortner.com trendingcharts.finance-analyst.com wellhealthtech.com -
twitter.com/h2jazi/status/1567247803184779266 · twitter.com/h2jazi/status/1567247805986574341 · virustotal.com/gui/file/e21362195463fe7c953afe07bea6a2… · virustotal.com/gui/file/08a8ecc39817a81bb9cde3775ce728…
neweconomysolution.com sun-tourist.com -
twitter.com/h2jazi/status/1543957383193444352 · virustotal.com/gui/file/58ff981332189a0a2e0b1152f36a5e… · virustotal.com/gui/file/467b59feba8ebaa7ef81b19ca69c13… · virustotal.com/gui/file/086e49e431272b1ea8e3c1d7a9e297…
domain thefinanceinvest.com url http://20.43.53.72 url_path /okceG -
twitter.com/h2jazi/status/1518629712364515329 · virustotal.com/gui/file/d767e2ba31b75714aeb1cc3995de91…
imagine-world.com -
twitter.com/malwrhunterteam/status/1233666708616941… · twitter.com/SBousseaden/status/1222465015975948289 · app.any.run/tasks/b63ec8f5-70a6-4379-97e9-acbe3ce5e… · app.any.run/tasks/4c404a75-4caf-430b-a901-c18bc8fb0… · securelist.com/wirtes-campaign-in-the-middle-east-livi… · otx.alienvault.com/pulse/61a4fb7c9b88f16b103c151d
allaccounting.ca doctoressolis.com est-clinic.com firstohiobank.com kneeexercises.net niftybuysellchart.com nutrition-information.org pocket-property.com -
twitter.com/malwrhunterteam/status/1233666708616941… · twitter.com/SBousseaden/status/1222465015975948289 · app.any.run/tasks/b63ec8f5-70a6-4379-97e9-acbe3ce5e… · app.any.run/tasks/4c404a75-4caf-430b-a901-c18bc8fb0… · securelist.com/wirtes-campaign-in-the-middle-east-livi… · otx.alienvault.com/pulse/61a4fb7c9b88f16b103c151d
stgeorgebankers.com -
twitter.com/malwrhunterteam/status/1233666708616941… · twitter.com/SBousseaden/status/1222465015975948289 · app.any.run/tasks/b63ec8f5-70a6-4379-97e9-acbe3ce5e… · app.any.run/tasks/4c404a75-4caf-430b-a901-c18bc8fb0… · securelist.com/wirtes-campaign-in-the-middle-east-livi… · otx.alienvault.com/pulse/61a4fb7c9b88f16b103c151d
unitedfamilyhealth.net -
twitter.com/malwrhunterteam/status/1233666708616941… · twitter.com/SBousseaden/status/1222465015975948289 · app.any.run/tasks/b63ec8f5-70a6-4379-97e9-acbe3ce5e… · app.any.run/tasks/4c404a75-4caf-430b-a901-c18bc8fb0… · securelist.com/wirtes-campaign-in-the-middle-east-livi… · otx.alienvault.com/pulse/61a4fb7c9b88f16b103c151d
omegaeyehospital.com -
twitter.com/malwrhunterteam/status/1233666708616941… · twitter.com/SBousseaden/status/1222465015975948289 · app.any.run/tasks/b63ec8f5-70a6-4379-97e9-acbe3ce5e… · app.any.run/tasks/4c404a75-4caf-430b-a901-c18bc8fb0… · securelist.com/wirtes-campaign-in-the-middle-east-livi… · otx.alienvault.com/pulse/61a4fb7c9b88f16b103c151d
domain dentalmatrix.net ipv4 104.28.1.134:2087 ipv4 172.86.75.211:80 -
securityartwork.es/2019/01/18/grupo-wirte-atacando-a-orien… · securityartwork.es/2019/01/25/wirte-group-attacking-the-mi…
104.24.108.64:2082 104.24.109.64:2082 185.86.79.243:2082 -
blog.talosintelligence.com/2018/02/targeted-attacks-in-middle-east… · twitter.com/SaudiDFIR/status/1119666633251930113 · twitter.com/James_inthe_box/status/1119932303088578… · twitter.com/MoBustami/status/1119959411156488192 · x.com/malwrhunterteam/status/1998743764630732… · virustotal.com/gui/file/d9dc90fd23cd2ad5e5a1b9df65d36f…
office365-update.com -
securityartwork.es/2019/01/18/grupo-wirte-atacando-a-orien… · securityartwork.es/2019/01/25/wirte-group-attacking-the-mi…
micorsoft.store office365-update.co -
blog.talosintelligence.com/2018/02/targeted-attacks-in-middle-east… · twitter.com/SaudiDFIR/status/1119666633251930113 · twitter.com/James_inthe_box/status/1119932303088578… · twitter.com/MoBustami/status/1119959411156488192 · x.com/malwrhunterteam/status/1998743764630732… · virustotal.com/gui/file/d9dc90fd23cd2ad5e5a1b9df65d36f…
foxlove.life office-update.services share2file.pro
Further reading 31
- attack.mitre.org/groups/G0090
- lab52.io/blog/wirte-group-attacking-the-middle-e…
- research.checkpoint.com/2024/hamas-affiliated-threat-actor-expa…
- securelist.com/wirtes-campaign-in-the-middle-east-livi…
- unit42.paloaltonetworks.com/hamas-affiliate-ashen-lepus-uses-new-ma…
- virustotal.com/gui/file/467b59feba8ebaa7ef81b19ca69c13…
- twitter.com/SaudiDFIR/status/1119666633251930113
- virustotal.com/gui/file/d9dc90fd23cd2ad5e5a1b9df65d36f…
- x.com/malwrhunterteam/status/1998743764630732…
- blog.talosintelligence.com/2018/02/targeted-attacks-in-middle-east…
- app.any.run/tasks/4c404a75-4caf-430b-a901-c18bc8fb0…
- twitter.com/malwrhunterteam/status/1233666708616941…
- virustotal.com/gui/file/58ff981332189a0a2e0b1152f36a5e…
- securityartwork.es/2019/01/25/wirte-group-attacking-the-mi…
- twitter.com/h2jazi/status/1567247805986574341
- twitter.com/SBousseaden/status/1222465015975948289
- securelist.com/wirtes-campaign-in-the-middle-east-livi…
- virustotal.com/gui/file/d767e2ba31b75714aeb1cc3995de91…
- virustotal.com/gui/file/086e49e431272b1ea8e3c1d7a9e297…
- securityartwork.es/2019/01/18/grupo-wirte-atacando-a-orien…
- app.any.run/tasks/b63ec8f5-70a6-4379-97e9-acbe3ce5e…
- otx.alienvault.com/pulse/61a4fb7c9b88f16b103c151d
- twitter.com/h2jazi/status/1518629712364515329
- x.com/k3yp0d/status/1857000802067345730
- virustotal.com/gui/file/08a8ecc39817a81bb9cde3775ce728…
- twitter.com/h2jazi/status/1543957383193444352
- twitter.com/h2jazi/status/1567247803184779266
- twitter.com/James_inthe_box/status/1119932303088578…
- twitter.com/MoBustami/status/1119959411156488192
- virustotal.com/gui/file/9979ed5993fb6d678727e6dacb15d2…
- virustotal.com/gui/file/e21362195463fe7c953afe07bea6a2…