BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

WIRTE APT Targets Middle East with AshTag Malware Since 2020

WIRTE's AshTag Malware Suite Targets Middle Eastern Governments for Espionage Amid Ongoing Regional Conflicts

  • An advanced persistent threat group named WIRTE has been using a new Malware suite called AshTag to attack Middle Eastern government and diplomatic targets since 2020.
  • Palo Alto Networks tracks this group as Ashen Lepus, which continues to operate actively, including during and after the 2025 Israel-Hamas conflict.
  • The campaign expanded its targets to Oman and Morocco, in addition to earlier focuses on Palestinian Authority, Jordan, Iraq, Saudi Arabia, and Egypt.
  • AshTag operates as a modular .NET backdoor enabling persistence and remote control by masquerading as legitimate software, and it is deployed via malicious emails carrying geopolitical lures.
  • The threat actor engages in espionage centered on intelligence collection, stealing sensitive documents using hands-on techniques and specialized tools for data exfiltration.

Since 2020, the advanced persistent threat group WIRTE has targeted government and diplomatic organizations across the Middle East with a previously unknown malware suite named AshTag. This campaign has been linked to espionage efforts aimed at intelligence collection. Palo Alto Networks identifies the activity cluster behind these attacks as Ashen Lepus.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

According to a detailed report shared with The Hacker News, Ashen Lepus expanded its operations to Oman and Morocco, broadening its geographical focus beyond the Palestinian Authority, Jordan, Iraq, Saudi Arabia, and Egypt. The group remained active even throughout the Israel-Hamas conflict of 2025 and continued deploying new malware variants after the October Gaza ceasefire.

WIRTE overlaps with groups such as Gaza Cyber Gang, also known by names like Blackstem, Molerats, and TA402, and has been active since at least 2018. These factions are politically motivated and linked to Hamas cyberwarfare divisions. Their attacks focus on espionage and intelligence gathering, frequently using phishing emails that contain geopolitical topics as bait. Recent email lures have targeted issues related to Turkey, suggesting a possible new focus area.

The attack starts with a decoy PDF attached to phishing emails, leading victims to download a RAR archive. This triggers a multi-stage infection that sideloads a malicious DLL named AshenLoader, which drops other components, including AshenStager, to execute the malware in memory. The AshTag backdoor is a modular .NET framework that enables persistence, remote command execution, screen capture, file management, system fingerprinting, and updating or removal of components. It disguises itself as a legitimate VisualServer utility to evade detection.

In some cases, Ashen Lepus operators have been observed manually accessing compromised machines to steal documents. Sensitive files, including diplomacy-related materials obtained from victim email inboxes, were staged locally and then exfiltrated to attacker-controlled servers using the Rclone utility.

- Advertisement -

As described, “Ashen Lepus remains a persistent espionage actor, demonstrating a clear intent to continue its operations throughout the recent regional conflict — unlike other affiliated threat groups, whose activity significantly decreased.” The group’s continued campaigns reflect a strong commitment to ongoing intelligence collection.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Pump.fun Restricts Creator Fee Changes To One

Pump.fun has limited memecoin creators to just one post-launch change to fee recipient wallets.The...

Cardano Rebounds, But $0.50 in Sight for 2026?

Cardano (ADA) has gained 3% in the last 24 hours but remains down 7.7%...

$35M in Bitcoin seized after police crack lost wallet

Irish police, with Europol's help, have seized 500 Bitcoin (worth over $35 million) from...

Gold Crashes to 4-Month Low; Strategists Keep $5K–$6.3K Targets

Gold crashed to a four-month low of $4,098, posting its worst five-session performance since...

Baltimore sues xAI over Grok’s millions of non-consensual deepfakes

The Mayor and City Council of Baltimore have sued X Corp., xAI, and SpaceX,...

Must Read

14 Ways On How to Make Money with Cryptocurrency

Many people want to make money with cryptocurrency because they have heard the success stories of people who became millionaires from zero.If you...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading