Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware SameCoin

SameCoin

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

SameCoin is a multi‑platform wiper used by the WIRTE group to target Israeli and other Middle Eastern entities, deleting critical system files on both Windows and Android devices. The malware’s destructive behavior indicates an intent for sabotage rather than data theft. Security teams should prioritize rapid backup verification and robust endpoint protection to mitigate potential loss.

Enhanced Description

SameCoin is a dual‑platform destructive malware that operates on both Windows and Android operating systems. Designed as a wiper, it systematically deletes critical system files and user data, effectively rendering infected devices inoperable. The tool has been linked to the threat actor group WIRTE (also known as WIRE) and has been employed in targeted campaigns against entities in the Middle East, including Israeli organizations—an attribution supported by Check Point’s 2024 Wirte analysis. While specific technical details are sparse, SameCoin follows typical wiper patterns: it silently initiates file‑system modifications and purges after confirming execution conditions. For Android, it exploits root privileges or leverages sideloaded APKs to wipe internal storage and user data; on Windows, the malware deletes registry entries, system services, and application files, accompanied by attempts to remove forensic evidence such as logs and remnants of its own code. The dual‑platform nature suggests an effort to maximize impact across different device ecosystems within the target networks. Beyond local destruction, preliminary reports indicate that SameCoin may log system information or exfiltrate basic metadata before wiping, potentially providing WIRTE with actionable intelligence regarding victim characteristics. Its presence in a broader campaign implies integration into automated attack frameworks featuring modular payload delivery and optional encryption to obscure command and control (C2) traffic.

Key Capabilities

  • Deletes critical Windows system files and registry entries
  • Systematically wipes user data on Android devices
  • Exfiltrates metadata or system information before wiping
  • Evades basic forensic detection by removing logs
  • Targets both desktop and mobile operating systems
  • Operates under the command of the WIRTE threat actor group

ATT&CK Techniques

T1485
T1070.004
T1059.001

Recommended Actions

  • Deploy up‑to‑date endpoint protection with signatures for SameCoin and its variants
  • Implement application whitelisting to block unauthorized installations on Windows and Android
  • Block known Domain/IP indicators linked to WIRTE C2 infrastructure
  • Perform regular, immutable backups of critical data and monitor backup integrity against ransomware/wiper metrics
  • Educate users about phishing or malicious app downloads that could install the same tool

Suggested Tags

SameCoin
Wiper
Windows
Android
MiddleEastTargeted
WIRTE
DestructiveMalware

Confidence Assessment

The available information confirms SameCoin’s existence as a dual‑platform wiper used by WIRTE in Middle Eastern campaigns, yet specific indicators such as file hashes, command–control domains or detailed behavioral logs are not provided. Consequently, confidence is moderate regarding its destructive capabilities but low concerning precise attack vectors and detection signatures due to the absence of granular technical data.

Description

SameCoin is a multi-platform wiper with Windows and Android versions that has been used by WIRTE to target entities in the Middle East including in Israel.(Citation: Check Point Wirte NOV 2024)

Details

Type
Malware
Platforms
Windows
Android
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.