Unit 42. (2025, December 11). Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite. Retrieved April 20, 2026.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareAshTag | The AshTag AshenOrchestrator component payload as been Base64 encoded and embedded with HTML content from the C2 server. |
| T1027.015 Compression |
GroupWIRTE | WIRTE has compressed malicious files within RAR and ZIP archives for obfuscation. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareAshTag | AshTag has masqueraded as a legitimate VisualServer utility. |
| T1041 Exfiltration Over C2 Channel |
MalwareAshTag | AshTag has exfiltrated reconnaissance data on targeted systems to C2 servers. |
| T1041 Exfiltration Over C2 Channel |
GroupWIRTE | WIRTE has exfiltrated collected victim data to C2 infrastructure. |
| T1047 Windows Management Instrumentation |
MalwareAshTag | AshTag can use a .NET program to execute WMI queries and send unique victim IDs to C2. |
| T1053.005 Scheduled Task |
MalwareAshTag | AshTag can set persistence using scheduled tasks. |
| T1057 Process Discovery |
MalwareAshTag | The AshTag AshenOrchestrator component has process management functionality. |
| T1059.007 JavaScript |
MalwareAshTag | AshTag can use JSON files to deliver payloads and configuration files. |
| T1071.001 Web Protocols |
MalwareAshTag | AshTag can use HTTP to send and receive data from C2. |
| T1074.001 Local Data Staging |
GroupWIRTE | WIRTE has staged collected documents of interest in `C:\Users\Public folder`. |
| T1082 System Information Discovery |
MalwareAshTag | The AshTag loader and AshenOrchestrator components can collect reconnaissance data from victim machines. |
| T1083 File and Directory Discovery |
MalwareAshTag | The AshTag AshenOrchestrator component can enumerate files on victim hosts. |
| T1102 Web Service |
MalwareAshTag | AshTag can download malicious payloads from file sharing services. |
| T1105 Ingress Tool Transfer |
MalwareAshTag | The AshTag stager component can retrieve and execute the main payload. |
| T1113 Screen Capture |
MalwareAshTag | The AshTag AshenOrchestrator component has the ability to take screenshots. |
| T1114.001 Local Email Collection |
GroupWIRTE | WIRTE has collected documents from victims' email accounts. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAshTag | The AshTag stager compoment can decode and decrypt Base64 and XOR-encrypted payloads. |
| T1204.002 Malicious File |
MalwareAshTag | AshTag has been executed through victims downloading and opening malicious RAR archive files. |
| T1204.002 Malicious File |
GroupWIRTE | WIRTE has attempted to lure users into opening malicious documents including MS Word and Excel files, at times using a decoy document to encourage execution of malicious payloads. |
| T1497.001 System Checks |
GroupWIRTE | WIRTE has configured C2 servers to check location and user-agent strings for victim endpoints to prevent sending a payload to sandboxed environments. |
| T1574.001 DLL |
MalwareAshTag | AshTag has enabled execution via DLL sideloading using a legitimate executable paired with a malicious DLL named wtsapi32. |
| T1583.001 Domains |
GroupWIRTE | WIRTE has registered domains designed to mimic legitimate sites for use in phishing campaigns. |
| T1588.002 Tool |
GroupWIRTE | WIRTE has obtained and used Empire and Rclone for post-exploitation activities. |
| T1608.001 Upload Malware |
GroupWIRTE | WIRTE has directed victims to malicious payloads staged on file sharing services. |
| T1614 System Location Discovery |
MalwareAshTag | AshTag can check geolocation on targeted systems. |
| T1678 Delay Execution |
MalwareAshTag | AshTag can use a set sleep time to delay C2 beaconing. |
| T1680 Local Storage Discovery |
MalwareAshTag | AshTag can use `volumeserialnumber` to enumerate volumes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.