AshTag is a modular multi-stage espionage malware suite used by the Hamas-affiliated threat group Ashen Lepus, also tracked as WIRTE, in campaigns against government and diplomatic entities across the Middle East, including targets in Palestine, Egypt, Jordan, Oman, and Morocco. The malware is designed to support long-term intelligence collection by stealing sensitive documents, maintaining access on compromised systems, and enabling remote operator tasking.
The framework is composed of a loader, a stager, and a .NET backdoor/orchestrator component, with support for additional modules. Reported functionality includes remote command execution, file theft and exfiltration, host profiling, screen capture, in-memory loading of follow-on components, and modular extension of capabilities. The malware emphasizes stealth through staged execution, encrypted and encoded payload delivery, and reduced disk artifacts. It has been observed masquerading as a legitimate utility and using an orchestrator component to manage communications and execute additional payloads in memory.
AshTag has been delivered through spearphishing campaigns using realistic Arabic-language diplomatic and geopolitical lures. Victims are enticed to open benign-looking documents that lead to archive downloads containing decoy content alongside malicious components. Execution commonly relies on DLL sideloading with a legitimate executable and malicious DLL, after which a harmless document is displayed to reduce suspicion while the malware continues in the background. Additional payloads and configuration data have been concealed within HTML content and recovered through decoding and decryption steps.
The malware reflects a notable maturation in Ashen Lepus tradecraft, combining social engineering, DLL sideloading, modular design, and in-memory execution to conduct persistent diplomatic espionage while blending command-and-control traffic with legitimate-looking web activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ashen Lepus deployed AshTag and AshenLoader targeting Palestine, Egypt, Jordan, Oman, and Morocco.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware deployed by Ashen Lepus in regional targeting operations.
Espionage backdoor used by WIRTE (Ashen Lepus) since 2020; delivered via AshenLoader sideloading per referenced title.
A modular, multi-stage malware suite designed for persistence, adaptability, and operational longevity, used by the Ashen Lepus threat group. It demonstrates professional-grade malware development and operational security.
AshTag is a modular backdoor used for espionage, delivered via DLL-sideloading chains, and is part of a toolkit used by the Hamas-affiliated Ashen Lepus (WIRTE) group for targeting Middle Eastern diplomatic entities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.