ATT&CKReferencesCheck Point Wirte NOV 2024

Check Point Wirte NOV 2024

Check Point. (2024, November 12). Hamas-affiliated Threat Actor WIRTE Continues its Middle East Operations and Moves to Disruptive Activity. Retrieved April 20, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples33

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
MalwareIronWind

IronWind has used Base64 encoding and XOR encryption with the key “53” to obfuscate command strings.

T1027.010
Command Obfuscation
GroupWIRTE

WIRTE has XOR encrypted command line strings to conceal malware execution chains.

T1027.010
Command Obfuscation
MalwareHavoc

Havoc has utilized XOR encryption with the key “01-01-1900” to obfuscate command strings.

T1027.015
Compression
GroupWIRTE

WIRTE has compressed malicious files within RAR and ZIP archives for obfuscation.

T1033
System Owner/User Discovery
MalwareIronWind

IronWind can enumerate the username on victim's systems.

T1036.005
Match Legitimate Resource Name or Location
GroupWIRTE

WIRTE has used security service provider naming conventions such as ESET and Kasperky ("Kaspersky Update Agent") in order to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwareSameCoin

SameCoin has named files to appear legitimate such as "MicrosoftEdge.exe."

T1053.005
Scheduled Task
MalwareSameCoin

SameCoin has the ability to set a scheduled task for execution.

T1059.003
Windows Command Shell
GroupWIRTE

WIRTE has used the Windows command line as part of infection chains to open documents.

T1059.003
Windows Command Shell
MalwareIronWind

IronWind has used the Windows command shell to execute malicious files.

T1070
Indicator Removal
MalwareIronWind

IronWind has used a .NET DLL named "exit-DN4-core.dll" to terminate malicious processes running on victim's systems.

T1071.001
Web Protocols
MalwareIronWind

IronWind can used HTTP to send information to C2 about the targeted system.

T1082
System Information Discovery
MalwareIronWind

IronWind can capture the OS version and computer name of the compromised host.

T1083
File and Directory Discovery
MalwareSameCoin

SameCoin can list all system files and can avoid wiping specific directories such as Program Files, Windows, and Users.

T1106
Native API
GroupWIRTE

WIRTE has used the `RtlIpv4StringToAddressA` to convert IP-formatted string to a byte array.

T1140
Deobfuscate/Decode Files or Information
MalwareIronWind

IronWind can deobfuscate the next stage payload using Base64 and XOR operations with the key "53".

T1204.001
Malicious Link
GroupWIRTE

WIRTE has used links embedded in emails to lure users into downloading malicious files.

T1204.002
Malicious File
MalwareHavoc

Havoc has been executed by victims through the use of targeted lures and crafted decoy documents.

T1204.002
Malicious File
GroupWIRTE

WIRTE has attempted to lure users into opening malicious documents including MS Word and Excel files, at times using a decoy document to encourage execution of malicious payloads.

T1485
Data Destruction
MalwareSameCoin

SameCoin can overwrite designated files on targeted systems with random bytes.

T1491.001
Internal Defacement
MalwareSameCoin

SameCoin can alter the victim’s background to display an image showing the name of Hamas’s military wing.

T1518
Software Discovery
MalwareIronWind

IronWind can list installed software on targeted hosts.

T1534
Internal Spearphishing
MalwareSameCoin

SameCoin can send its Setup.exe file as an attachment to other addresses in the same compromised organization.

T1566.002
Spearphishing Link
GroupWIRTE

WIRTE has sent targeted spearphishing emails with malicious links directing victims to malware downloads.

T1570
Lateral Tool Transfer
MalwareSameCoin

SameCoin can copy its wiper executable to remote machines within the same Active Directory.

T1574.001
DLL
MalwareIronWind

IronWind has used DLL sideloading for execution.

T1574.001
DLL
MalwareHavoc

Havoc has leveraged legitimate executables to side-load malicious payloads.

T1574.001
DLL
GroupWIRTE

WIRTE has used RAR archives containing a legitimate executable and a lure document to execute malicious DLLs via sideloading.

T1583.001
Domains
GroupWIRTE

WIRTE has registered domains designed to mimic legitimate sites for use in phishing campaigns.

T1586.002
Email Accounts
GroupWIRTE

WIRTE has used compromised emails, including one belonging to an Israel-based technology reseller, to deliver targeted spearphishing messages.

T1614
System Location Discovery
MalwareSameCoin

SameCoin can attempt to connect to the Israel Home Front Command site, oref.org[.]il, which is only reachable from within Israel to verify the target's location.

T1679
Selective Exclusion
MalwareSameCoin

SameCoin can avoid overwriting file names that contain “desktop.ini” and “conf.conf."

T1684.001
Impersonation
GroupWIRTE

WIRTE has used utilized look-alike domains and graphics of trusted security solution providers to entice victims to click on phishing links.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.