IronWind — Malware Profile
IronWind is a custom loader malware that has been in use since at least 2023 by actors including WIRTE to target entities in the Middle East.
MITRE ATT&CK techniques (9)
- T1027.010 Command Obfuscation
- T1033 System Owner/User Discovery
- T1059.003 Windows Command Shell
- T1070 Indicator Removal
- T1071.001 Web Protocols
- T1082 System Information Discovery
- T1140 Deobfuscate/Decode Files or Information
- T1518 Software Discovery
- T1574.001 DLL