WIRTE, also tracked as Frankenstein and ALUMINUM THORN, is a Palestine-attributed espionage threat actor active since at least 2018. The group has been associated with targeted phishing operations and appears to focus on narrowly scoped intelligence collection, particularly in the Middle East. Reporting indicates that its operations have at times remained relatively limited in scale, which may have reduced broader visibility across the security community. The actor is known for using commodity and open-source tooling, including FruityC2 and PowerShell Empire, and for combining publicly available code and techniques into its intrusion tradecraft. Its activity has been linked to phishing-based initial access and subsequent post-compromise operations consistent with espionage objectives. In 2024, the group was observed targeting government and defense entities in the Middle East through targeted phishing. Earlier reporting also associated its lure themes with regional targeting in the MENA space, including indications related to Jordan and Egypt, though those country-level targets are less firmly established than the broader Middle East focus. WIRTE is best characterized as a regional cyber-espionage actor aligned with Palestinian interests or operating from Palestine, with tradecraft centered on initial access via phishing, persistence and post-exploitation using established offensive frameworks, and collection-oriented intrusions against public-sector and defense-related targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage threat group profiled in the listing.
Espionage-focused activity cluster operating since at least Aug 2018, associated with the 'Frankenstein' campaign; conducts targeted phishing against government and defense entities in the Middle East/North Africa (MENA).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.