Attacks with the newly discovered AshTag malware suite have been launched by Hamas-affiliated advanced persistent threat operation WIRTE, also known as Ashen Lepus, against over a dozen Middle Eastern government and diplomatic organizations since 2020, The Hacker News reports.
Geopolitical-themed phishing emails were leveraged by WIRTE to spread a harmless PDF decoy luring targets into downloading a RAR archive, which contains a benign binary sideloading the AshenLoader DLL that deploys a legitimate executable and the AshenStager DLL to subsequently execute the AshTag backdoor, findings from a Palo Alto Networks Unit 42 report showed. Moreover, the AshenOrchestrator allows AshTag to inject additional payloads permitting persistence, screen capturing, updates and removal, file management, and system fingerprinting.
Such findings highlight the persistent cyberespionage activities of WIRTE, which has been linked to the Gaza Cyber Gang.
"The threat actors' activities throughout the last two years in particular highlight their commitment to constant intelligence collection," said Unit 42 researchers.
Geopolitical-themed phishing emails were leveraged by WIRTE to spread a harmless PDF decoy luring targets into downloading a RAR archive, which contains a benign binary sideloading the AshenLoader DLL that deploys a legitimate executable and the AshenStager DLL to subsequently execute the AshTag backdoor, findings from a Palo Alto Networks Unit 42 report showed. Moreover, the AshenOrchestrator allows AshTag to inject additional payloads permitting persistence, screen capturing, updates and removal, file management, and system fingerprinting.
Such findings highlight the persistent cyberespionage activities of WIRTE, which has been linked to the Gaza Cyber Gang.
"The threat actors' activities throughout the last two years in particular highlight their commitment to constant intelligence collection," said Unit 42 researchers.



