logo

Hamas-Linked Hackers Probe Middle Eastern Diplomats

ID: cbe53a79-9035-55bc-b883-1fe32dd70adf

STIX ID: report--cbe53a79-9035-55bc-b883-1fe32dd70adf

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-12-12

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Unit 42 documents a Hamas-affiliated APT (Wirte / Ashen Lepus) conducting persistent espionage across Middle Eastern governmental and diplomatic targets since 2018; the group has developed a modular malware suite named AshTag that uses phishing PDFs, DLL sideloading, HTML-embedded and commented-out payload storage, and strong encryption to evade detection, and has recently expanded its geographic scope and lure themes, indicating a broader operational footprint and sustained threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.