← Back to Actors
WIRTE
WIRTEAshen Lepus
[WIRTE](https://attack.mitre.org/groups/G0090) is a cyberespionage actor, believed to be a subgroup of the Hamas-affiliated Gaza Cybergang, that has been active since at least August 2018. [WIRTE](https://attack.mitre.org/groups/G0090) has targeted diplomatic, financial, military, legal, and technology organizations across the Middle East, North Africa, and in Europe to gather intelligence. [WIRTE](https://attack.mitre.org/groups/G0090) has remained persistently active despite the ongoing Israel-Hamas conflict and has expanded their operations to include wiper malware attacks against Israeli t...
26
Techniques
24
Covered
2
Gaps
92%
Coverage
Coverage24/26
COVERED (24)
T1027.010Command Obfuscation38 det.T1027.015Compression2 det.T1036.005Match Legitimate Resource Name or Location45 det.T1041Exfiltration Over C2 Channel32 det.T1059.001PowerShell376 det.T1059.003Windows Command Shell87 det.T1059.005Visual Basic70 det.T1071.001Web Protocols81 det.T1074.001Local Data Staging10 det.T1105Ingress Tool Transfer191 det.T1106Native API29 det.T1114.001Local Email Collection11 det.T1140Deobfuscate/Decode Files or Information58 det.T1204.001Malicious Link11 det.T1204.002Malicious File461 det.T1218.010Regsvr3243 det.T1497.001System Checks6 det.T1566.001Spearphishing Attachment1055 det.T1566.002Spearphishing Link1086 det.T1571Non-Standard Port17 det.T1574.001DLL111 det.T1583.001Domains68 det.T1588.002Tool13 det.T1608.001Upload Malware3 det.