WIRTE Leverages AshenLoader Sideloading to Install the AshTag Espionage Backdoor
Since 2020, WIRTE, an advanced persistent threat (APT), has been linked to strikes against Middle Eastern governments and diplomatic institutions using an unreported malware suite called AshTag.
The activity cluster is being monitored by Palo Alto Networks under the name Ashen Lepus. The threat actor has fixed its eyes on Oman and Morocco, according to artifacts published to the VirusTotal platform. This suggests that the threat actor's operational scope has expanded beyond the Palestinian Authority, Jordan, Iraq, Saudi Arabia, and Egypt.
According to a study provided with The Hacker News, Ashen Lepus continued to be active throughout the Israel-Hamas conflict, setting it apart from other linked groups whose activities declined around the same time. Even after the ceasefire in Gaza ...


