Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite

Summary: The threat actor group Ashen Lepus, associated with Hamas, has launched a new malware suite called AshTag against Middle Eastern diplomatic entities.

In recent months, we have been analyzing the activity of an advanced persistent threat (APT) known for its espionage activities against Arabic-speaking government entities. We track this Middle Eastern threat actor as Ashen Lepus (aka WIRTE). We share details of a long-running, elusive espionage campaign targeting governmental and diplomatic entities throughout the Middle East. We discovered that the group has created new versions of their previously documented custom loader, delivering a new malware suite that we have named AshTag. The group has also updated their command and control (C2) architecture to evade analysis and blend in with legitimate internet traffic.

Ashen Lepus remained persistently active throughout the Israel-Hamas conflict, distinguishing it from other affiliated groups whose activities decreased over the same period. Ashen Lepus continued with its campaign even after the October 2025 Gaza ceasefire, deploying newly developed malware variants and engaging in hands-on activity within victim environments.

This campaign highlights a tangible evolution in Ashen Lepus's operational security and tactics, techniques, and procedures (TTPs). While its operations over the years have demonstrated only moderate sophistication, the group has recently adopted more advanced tactics that include:
- Enhanced custom payload encryption
- Infrastructure obfuscation using legitimate subdomains
- In-memory execution to minimize forensic artifacts

Key facts

  • Ashen Lepus is an APT group associated with Hamas
  • A new AshTag malware suite was developed to target Middle Eastern entities
  • The group has enhanced its operational security and tactics over time
  • Continued activity during the Israel-Hamas conflict

Why it matters

The persistence and sophistication of Ashen Lepus' operations pose a significant cyber threat to Middle Eastern governments and diplomatic entities, potentially compromising sensitive information. This highlights the need for robust cybersecurity measures and continuous monitoring to protect against such threats.