From 59930c1b0b6a3019eef4f7e67ae9b97ce56ca27c Mon Sep 17 00:00:00 2001 From: Mathieu4141 Date: Mon, 13 Nov 2023 04:36:56 -0800 Subject: [PATCH] [threat-actors] Add WIRTE --- clusters/threat-actor.json | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index e27239f..aaabd00 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -12870,6 +12870,18 @@ }, "uuid": "7ba756f0-0753-4da9-b00d-8cf35ba84e57", "value": "WeRedEvils" + }, + { + "description": "WIRTE is a threat actor group that was first discovered in 2018. They are suspected to be part of the Gaza Cybergang, an Arabic politically motivated cyber criminal group. WIRTE has been observed changing their toolkit and operating methods to remain undetected for longer periods of time. They primarily target governmental and political entities, but have also been known to target law firms and financial institutions.", + "meta": { + "country": "PS", + "refs": [ + "https://securelist.com/wirtes-campaign-in-the-middle-east-living-off-the-land-since-at-least-2019/105044/", + "https://lab52.io/blog/wirte-group-attacking-the-middle-east/" + ] + }, + "uuid": "ec6bcaa9-4cb3-4397-a735-c806bc986c81", + "value": "WIRTE" } ], "version": 293