Skip to main content
Mallory
Back to malware
MalwareUsed by 1 actor

AshenLoader

AshenLoader is a malicious DLL loader used in the AshTag espionage malware chain operated by the Hamas-affiliated threat group Ashen Lepus, also tracked as WIRTE. It has been used in campaigns targeting governmental and diplomatic entities in the Middle East, including reported targeting of Palestine, Egypt, Jordan, Oman, and Morocco. The infection chain described in the source material is AshenLoader -> AshenStager -> AshenOrchestrator, culminating in deployment of the modular AshTag backdoor.

Delivery relies on diplomatic-themed lures and DLL sideloading. Victims are enticed with benign-looking PDF documents that lead to download of RAR archives containing a fake document executable, a malicious DLL identified as AshenLoader, and a decoy PDF. A renamed benign executable is used to sideload the AshenLoader DLL. When executed, AshenLoader opens a harmless decoy PDF to reduce suspicion, collects basic host information, contacts an external server, and retrieves or drops additional components. Reported follow-on payloads include a legitimate executable and a DLL payload called AshenStager (also referred to as stagerx64), which is again sideloaded to continue execution.

The broader malware suite emphasizes stealth and in-memory execution to minimize forensic artifacts on disk. AshenLoader fetches content hidden in HTML, including data embedded between custom tags, which is then used to deliver later stages. Subsequent components extract Base64-encoded payloads and configuration data, including C2 domains, module URLs, encryption keys, and timing values. The final AshTag framework supports espionage functions including file exfiltration, command execution, persistence, process management, update and removal, screen capture, file management, and system fingerprinting via WMI. Observed infrastructure included API-style subdomains on legitimate-looking sites, with examples such as api.healthylifefeed[.]com and auth.onlinefieldtech[.]com. Reported post-compromise activity included staging stolen diplomatic documents in C:\Users\Public and exfiltrating them with Rclone.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Molerats

Ashen Lepus deployed AshTag and AshenLoader targeting Palestine, Egypt, Jordan, Oman, and Morocco.

via centripetal threat researchcentripetal.ai
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.