PULSE NAME
Hamas-affiliated Threat Actor WIRTE Continues its Middle East Operations and Moves to Disruptive Activity
WHITE WIRTE AlienVault 2024-11-12 Modified: 2024-12-12
91
IOCs
HIGH VOLUME
Check Point Research has been tracking ongoing activity of the WIRTE threat actor, associated with Hamas, despite the ongoing conflict in the region. The group continues to target entities in the Palestinian Authority, Jordan, Iraq, Egypt, and Saudi Arabia for espionage. WIRTE has expanded its operations to include disruptive attacks, with clear links found between their custom malware and the SameCoin wiper targeting Israeli entities. The group's tools have evolved, but key operational aspects remain consistent. WIRTE's activities persist throughout the war, complicating geographical attribution. The group employs various tactics, including custom loaders, phishing, and wipers, targeting both Israeli and other Middle Eastern entities.
Indicators of Compromise (8 / 91 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0e0a2ab9622d73cb7ce5bb81453fc67a 2024-11-12
FileHash-MD5 0e24fa3bb4de4977e68fa4438c025d9d 2024-11-12
FileHash-MD5 4a231b7fe78a606307a038ca3140a19b 2024-11-12
FileHash-MD5 66572a740d26abf3ea131704957ff7a6 2024-11-12
FileHash-MD5 88915eb58dc887d639845f3812338534 2024-11-12
FileHash-MD5 89f7d22009ba38b71aaa23db348e2ee1 2024-11-12
FileHash-MD5 ab0867d5376a12f00ca5fd06d628f8f4 2024-11-12
FileHash-MD5 f321fcbfa16d92fde8c4bad1b0968140 2024-11-12