Ashen Lepus Hacker Group Attacks Eastern Diplomatic Entities With New AshTag Malware
ID: 7ad11547-187c-5244-912a-7a8d177fb7e8
STIX ID: report--7ad11547-187c-5244-912a-7a8d177fb7e8
Feed Name: cybersecurityNews.com
Threat Score
A Palo Alto Networks–sourced report describes an ongoing espionage campaign by Hamas‑affiliated Ashen Lepus using Arabic diplomatic lures to deliver a modular .NET backdoor called AshTag; attackers employ benign‑looking PDFs and RAR archives (fake executables and decoy PDFs), DLL sideloading, in‑memory payload execution, and API‑style subdomains for C2 to stealthily exfiltrate diplomatic documents and maintain persistent access across the region.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
