WIRTE is a politically motivated threat actor, likely part of Gaza Cybergang, targeting governments with custom malware and spearphishing.
Analyst brief
WIRTE is a threat actor group first discovered in 2018, likely part of the politically motivated Gaza Cybergang. They primarily target governmental and political entities, but also hit law firms and financial institutions. Their TTPs include spearphishing attachments/links for initial access, PowerShell and Visual Basic for execution, and web protocols with non-standard ports for C2; they leverage custom malware like LitePower, Ferocious, and Havoc, along with tools such as Empire and Rclone. Defenders should focus on suspicious spearphishing emails, anomalous PowerShell script execution, and data exfiltration over C2 channels.
WIRTE
Ashen Lepus
unknown
WIRTE is a threat actor group that was first discovered in 2018. They are suspected to be part of the Gaza Cybergang, an Arabic politically motivated cyber criminal group. WIRTE has been observed changing their toolkit and operating methods to remain undetected for longer periods of time. They primarily target governmental and political entities, but have also been known to target law firms and financial institutions.