WIRTE Group is a politically motivated cyber espionage group that has been active since at least August 2018, primarily targeting entities across the Middle East. Initially focused on information theft and espionage, the group has recently expanded its operations to include disruptive attacks, notably employing wiper malware. WIRTE is widely assessed with high confidence to be a subgroup connected to the Hamas-affiliated Gaza Cybergang. The group is distinguished by its operational blend of relatively unsophisticated yet effective techniques, often utilizing unobtrusive scripts and unencrypted HTTP communications, alongside custom malware and living-off-the-land binaries to achieve its objectives despite lacking overtly complex infrastructure. They frequently use Arabic-themed decoy documents to enhance their social engineering tactics and lure victims.