AshenStager is a DLL-based staging component in the AshTag malware suite used by the Hamas-affiliated espionage group Ashen Lepus, also tracked as WIRTE. It appears in a multi-stage infection chain of AshenLoader -> AshenStager -> AshenOrchestrator targeting governmental and diplomatic entities across the Middle East, including activity affecting countries such as Oman and Morocco. The broader campaign uses realistic Arabic-language diplomatic lures, where benign-looking PDFs lead victims to download RAR archives containing a fake document executable, a malicious loader, and a decoy PDF. Infection relies on DLL side-loading, and a harmless PDF is opened to reduce suspicion.
According to the provided content, AshenLoader sends basic host data to command-and-control infrastructure and retrieves AshenStager from HTML content hidden between custom headerp tags. AshenStager then requests another page and extracts a Base64-encoded payload embedded inside article tags. It is described as a DLL payload, also referred to as stagerx64, that is sideloaded and used to launch the malware suite in memory, minimizing forensic artifacts on disk. This staging behavior supports the delivery of later components, including AshenOrchestrator, which manages encrypted configuration data, module loading, and modular capabilities.
The malware suite associated with AshenStager is described as a modular .NET backdoor masquerading as a VisualServer utility and supporting capabilities such as command execution, file exfiltration, in-memory loading of additional tools, persistence, process management, update and removal, screen capture, file management, and system fingerprinting. Recovered modules include SN for host profiling via WMI and SCT for screen capture. The campaign is focused on long-term intelligence collection and theft of sensitive diplomatic documents. Observed infrastructure includes API-style subdomains on legitimate-looking sites, with examples including api.healthylifefeed[.]com and auth.onlinefieldtech[.]com.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Second-stage stager that requests additional web content and extracts a Base64-encoded payload embedded in HTML (e.g., within <article> tags) to deliver the orchestration component.
AshenStager (stagerx64) is a DLL payload used to launch the AshTag malware suite in memory, supporting stealthy deployment and minimizing disk artifacts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.