logo

Hamas-affiliated Threat Actor WIRTE Continues its Middle East Operations and Moves to Disruptive Activity

ID: f814ff10-f287-5d8b-a4da-f1d7fd1b4eda

STIX ID: report--f814ff10-f287-5d8b-a4da-f1d7fd1b4eda

Feed Name: Check Point Research

Threat Score
84/100

Date Published: 2024-11-12

Date Updated: 2026-04-27

Author: [email protected]

...
...

Check Point Research analyzes WIRTE, a Middle Eastern APT likely aligned with Hamas, documenting persistent 2024 campaigns that combine espionage (IronWind loader, Havoc backdoor) with disruptive SameCoin wiper operations against Israeli targets; the report includes technical analysis of infection chains (DLL sideloading, HTML-embedded payloads, user-agent filtered C2), detailed infrastructure and IOCs, victimology across the Palestinian Authority, Jordan, Iraq, Egypt and Saudi Arabia, and operational attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.