← Back to Actors
WIRTE
WIRTEAshen Lepus
[WIRTE](https://attack.mitre.org/groups/G0090) is a cyberespionage actor, believed to be a subgroup of the Hamas-affiliated Gaza Cybergang, that has been active since at least August 2018. [WIRTE](https://attack.mitre.org/groups/G0090) has targeted diplomatic, financial, military, legal, and technology organizations across the Middle East, North Africa, and in Europe to gather intelligence. [WIRTE](https://attack.mitre.org/groups/G0090) has remained persistently active despite the ongoing Israel-Hamas conflict and has expanded their operations to include wiper malware attacks against Israeli t...
26
Techniques
24
Covered
2
Gaps
92%
Coverage
Coverage24/26
COVERED (24)
T1027.010Command Obfuscation38 det.T1027.015Compression2 det.T1036.005Match Legitimate Resource Name or Location44 det.T1041Exfiltration Over C2 Channel31 det.T1059.001PowerShell368 det.T1059.003Windows Command Shell82 det.T1059.005Visual Basic68 det.T1071.001Web Protocols80 det.T1074.001Local Data Staging10 det.T1105Ingress Tool Transfer183 det.T1106Native API29 det.T1114.001Local Email Collection11 det.T1140Deobfuscate/Decode Files or Information58 det.T1204.001Malicious Link10 det.T1204.002Malicious File425 det.T1218.010Regsvr3243 det.T1497.001System Checks6 det.T1566.001Spearphishing Attachment905 det.T1566.002Spearphishing Link904 det.T1571Non-Standard Port16 det.T1574.001DLL109 det.T1583.001Domains61 det.T1588.002Tool13 det.T1608.001Upload Malware3 det.