WIRTE is a cyber-espionage threat cluster associated with malware staging and backdoor activity linked by multiple researchers to the broader Gaza Cybergang ecosystem. It has been connected through overlapping tradecraft and command-and-control characteristics with TA402 and other Gaza Cybergang-associated operations, suggesting operational or developmental relationships rather than a clearly distinct standalone malware family. Activity attributed to WIRTE has focused on intelligence collection, with observed tooling using scripted staging components and custom network communication patterns.
Observed WIRTE-associated malware staging has included VBS-based components that decode Base64-embedded documents or payload material during execution. Network communications have used HTTP as well as HTTPS over non-standard ports, and WIRTE has been noted for a distinctive custom user-agent format used during staging communications, with fields that likely encode intrusion-specific identifiers. Reporting also notes an infinite-loop style C2 communication pattern with randomized sleep intervals in related tooling that shares WIRTE-specific artifacts.
Because WIRTE is primarily tracked as a threat actor or intrusion set rather than a single well-defined malware family, its tooling is best characterized as espionage-oriented backdoor and staging malware used against regional targets. Available information supports use of obfuscation reversal and staged delivery techniques, but does not establish a single canonical malware family name beyond the operator designation itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
WIRTE is known for using a unique custom user agent for C2 communication when staging malware, with the value of the rv field likely being an intrusion identifier.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/tool or cluster referenced with alias Ashen Lepus.
Malware/staging tooling associated with the WIRTE cluster, characterized by a unique custom user agent and infinite-loop C2 communication pattern with randomized sleep intervals. Similar artifacts were observed in TA402 .NET stagers, suggesting overlap with Gaza Cybergang-related activity.
Malware that decodes a Base64-encoded document embedded in a VBS script.
Malware that uses HTTP for network communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.