ATT&CKReferencesPalo Alto Ashen Lepus DEC 2025

Palo Alto Ashen Lepus DEC 2025

Unit 42. (2025, December 11). Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite. Retrieved April 20, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples28

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareAshTag

The AshTag AshenOrchestrator component payload as been Base64 encoded and embedded with HTML content from the C2 server.

T1027.015
Compression
GroupWIRTE

WIRTE has compressed malicious files within RAR and ZIP archives for obfuscation.

T1036.005
Match Legitimate Resource Name or Location
MalwareAshTag

AshTag has masqueraded as a legitimate VisualServer utility.

T1041
Exfiltration Over C2 Channel
MalwareAshTag

AshTag has exfiltrated reconnaissance data on targeted systems to C2 servers.

T1041
Exfiltration Over C2 Channel
GroupWIRTE

WIRTE has exfiltrated collected victim data to C2 infrastructure.

T1047
Windows Management Instrumentation
MalwareAshTag

AshTag can use a .NET program to execute WMI queries and send unique victim IDs to C2.

T1053.005
Scheduled Task
MalwareAshTag

AshTag can set persistence using scheduled tasks.

T1057
Process Discovery
MalwareAshTag

The AshTag AshenOrchestrator component has process management functionality.

T1059.007
JavaScript
MalwareAshTag

AshTag can use JSON files to deliver payloads and configuration files.

T1071.001
Web Protocols
MalwareAshTag

AshTag can use HTTP to send and receive data from C2.

T1074.001
Local Data Staging
GroupWIRTE

WIRTE has staged collected documents of interest in `C:\Users\Public folder`.

T1082
System Information Discovery
MalwareAshTag

The AshTag loader and AshenOrchestrator components can collect reconnaissance data from victim machines.

T1083
File and Directory Discovery
MalwareAshTag

The AshTag AshenOrchestrator component can enumerate files on victim hosts.

T1102
Web Service
MalwareAshTag

AshTag can download malicious payloads from file sharing services.

T1105
Ingress Tool Transfer
MalwareAshTag

The AshTag stager component can retrieve and execute the main payload.

T1113
Screen Capture
MalwareAshTag

The AshTag AshenOrchestrator component has the ability to take screenshots.

T1114.001
Local Email Collection
GroupWIRTE

WIRTE has collected documents from victims' email accounts.

T1140
Deobfuscate/Decode Files or Information
MalwareAshTag

The AshTag stager compoment can decode and decrypt Base64 and XOR-encrypted payloads.

T1204.002
Malicious File
MalwareAshTag

AshTag has been executed through victims downloading and opening malicious RAR archive files.

T1204.002
Malicious File
GroupWIRTE

WIRTE has attempted to lure users into opening malicious documents including MS Word and Excel files, at times using a decoy document to encourage execution of malicious payloads.

T1497.001
System Checks
GroupWIRTE

WIRTE has configured C2 servers to check location and user-agent strings for victim endpoints to prevent sending a payload to sandboxed environments.

T1574.001
DLL
MalwareAshTag

AshTag has enabled execution via DLL sideloading using a legitimate executable paired with a malicious DLL named wtsapi32.

T1583.001
Domains
GroupWIRTE

WIRTE has registered domains designed to mimic legitimate sites for use in phishing campaigns.

T1588.002
Tool
GroupWIRTE

WIRTE has obtained and used Empire and Rclone for post-exploitation activities.

T1608.001
Upload Malware
GroupWIRTE

WIRTE has directed victims to malicious payloads staged on file sharing services.

T1614
System Location Discovery
MalwareAshTag

AshTag can check geolocation on targeted systems.

T1678
Delay Execution
MalwareAshTag

AshTag can use a set sleep time to delay C2 beaconing.

T1680
Local Storage Discovery
MalwareAshTag

AshTag can use `volumeserialnumber` to enumerate volumes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.