AshTag — Malware Profile

AshTag is a modular .NET backdoor with multiple features that has been used by WIRTE since at least 2025. AshTag is designed for persistence and remote command execution and can masquerade as a legitimate VisualServer utility.

MITRE ATT&CK techniques (19)

Attributed threat actors

Read the full analysis on IntelFusions