WIRTE is a cyber-espionage threat actor focused on Arabic-speaking individuals and organizations with an interest in Middle East affairs. Activity associated with the group dates to at least 2019. The actor has used phishing and macro-enabled lure documents themed around regional political and current-events topics, including subjects related to Palestine, Lebanon, and Iraq, to gain initial access and deliver malware. WIRTE has been linked through infrastructure overlap to the Gaza Cybergang, indicating operational or ecosystem relationships within the broader Middle East threat landscape. The group is primarily associated with targeted surveillance and intelligence collection rather than financially motivated operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.