Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
“Gaza Cybergang” is a threat-intelligence label, not a conclusively defined organization. MITRE ATT&CK lists it as an associated name for Molerats, while Check Point Research assesses the related WIRTE cluster as likely connected to Hamas. That is an analytic attribution—not proof that Hamas directs every operation reported under these names, or that the activity originated in Gaza.
Who is Gaza Cybergang?
MITRE ATT&CK tracks Molerats as Group G0021. Its profile describes an Arabic-speaking, politically motivated group active since 2012, with victims primarily in the Middle East, Europe and the United States. MITRE lists “Gaza Cybergang” and “Operation Molerats” as associated names. The entry is version 2.1 and was last modified on 31 July 2026.
That mapping is a structured tracking relationship, not a guarantee that every report using “Gaza Cybergang” or “Molerats” describes the same operators. Security firms and institutions have used overlapping labels for related activity, including Gaza Hack Team, Gaza Hackers Team and Extreme Jackal. Comparisons are clearest when they specify which source’s cluster name and alias mapping they mean.
Is Gaza Cybergang connected to Hamas?
Check Point Research’s November 2024 report says WIRTE is believed to be a subgroup connected to Gaza Cybergang and notes historical associations between WIRTE, Molerats and Gaza Cybergang. Check Point assesses WIRTE as likely connected to Hamas. Its reasoning includes messaging in disruptive attacks, recurring targeting of the Palestinian Authority, and historical ties to groups associated with Hamas.
#1 Best Overall
These are researchers’ assessments based on reported activity and relationships, not public proof of organizational command or control. Check Point says WIRTE’s continued activity during the Gaza war strengthened its assessment of Hamas affiliation while making it harder to attribute the activity geographically to Gaza specifically. Accordingly, “attributed to Hamas” should be read as a qualified intelligence judgment, not a confirmed identity claim about all operators tracked under overlapping names.
What attacks have been reported?
Espionage campaigns
Check Point reports WIRTE activity documented from 2019, including politically themed phishing lures and tools such as the IronWind loader. Earlier IronWind infection chains used a lure PDF, a legitimate executable and a malicious DLL; the report says victim system information was sent to attacker infrastructure.
In a campaign Check Point observed from late 2023, targets included entities in the Palestinian Authority, Jordan, Egypt, Iraq and Saudi Arabia. A September 2024 case study describes a PDF lure and archive-based infection chain that led to the Havoc post-exploitation framework. These are reported campaign observations, not evidence that every operation attributed to WIRTE used the same tools or targeted the same countries.
Disruptive attacks against Israeli entities
Check Point reports at least two waves of disruptive attacks against Israeli entities, in February and October 2024, and links custom malware to a wiper it calls SameCoin. According to the report, the wiper activated only when the target country was Israel or the system language was Hebrew. Check Point distinguishes this disruptive activity from WIRTE’s espionage operations, citing different targets and payloads as evidence of separate operational purposes. This account is the vendor’s assessment, not a court or government finding.
Rank #3
The 2019 cyber-unit strike claim
A 7 May 2019 CERT-EU memo recounted the Israeli military’s claim that it had thwarted a cyber offensive and struck a building where Hamas cyber operatives worked. The IDF spokesperson’s statement, as quoted in the memo, said: “HamasCyberHQ.exe has been removed.” The memo provides contemporaneous context about public claims and overlapping threat labels; it does not establish that the struck facility belonged to a specifically identified Gaza Cybergang cluster.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What techniques have researchers observed?
MITRE’s Molerats profile maps a range of techniques collected from cited reporting. These include phishing links and attachments, malicious files, PowerShell, VBScript and JavaScript, scheduled tasks and startup-folder persistence, browser credential collection, process discovery, and transfer of malicious files. The profile describes group-level observations: it does not mean each technique appeared in every campaign.
Rank #4
For WIRTE, Check Point describes additional delivery and infrastructure patterns: retrieving later-stage payloads from HTML elements, filtering command-and-control responses by user agent, redirecting other requests to legitimate websites, and using Cloudflare. Its reporting also notes domain-name themes involving health, finance and regional countries. Such patterns can inform investigation, but they are not a complete signature for every operation, and infrastructure details may change over time.
Recommended Free Tools
Quick Recap
Best Value
How to interpret the attribution
- Separate the labels. “Molerats,” “Gaza Cybergang” and “WIRTE” are related in some reporting, but should not be treated as interchangeable names for a definitively bounded organization.
- Distinguish evidence from assessment. A technique overlap or historical association is not the same as proof of shared command, and Check Point’s Hamas link is an attributed analytic judgment.
- Keep time and geography attached. WIRTE reporting covers espionage in several Middle Eastern countries and disruptive activity against Israeli entities; neither establishes that all activity originated in Gaza.
- Do not infer scale from examples. The cited accounts describe campaigns, targets and waves, but do not establish an aggregate victim count or total number of attacks.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

