logo

Ashen Lepus Hacker Group Attacks Eastern Diplomatic Entities With New AshTag Malware

ID: 7ad11547-187c-5244-912a-7a8d177fb7e8

STIX ID: report--7ad11547-187c-5244-912a-7a8d177fb7e8

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-12-12

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A Palo Alto Networks–sourced report describes an ongoing espionage campaign by Hamas‑affiliated Ashen Lepus using Arabic diplomatic lures to deliver a modular .NET backdoor called AshTag; attackers employ benign‑looking PDFs and RAR archives (fake executables and decoy PDFs), DLL sideloading, in‑memory payload execution, and API‑style subdomains for C2 to stealthily exfiltrate diplomatic documents and maintain persistent access across the region.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.