Executive Summary
SameCoin is a multi‑platform wiper used by the WIRTE group to target Israeli and other Middle Eastern entities, deleting critical system files on both Windows and Android devices. The malware’s destructive behavior indicates an intent for sabotage rather than data theft. Security teams should prioritize rapid backup verification and robust endpoint protection to mitigate potential loss.
Enhanced Description
SameCoin is a dual‑platform destructive malware that operates on both Windows and Android operating systems. Designed as a wiper, it systematically deletes critical system files and user data, effectively rendering infected devices inoperable. The tool has been linked to the threat actor group WIRTE (also known as WIRE) and has been employed in targeted campaigns against entities in the Middle East, including Israeli organizations—an attribution supported by Check Point’s 2024 Wirte analysis. While specific technical details are sparse, SameCoin follows typical wiper patterns: it silently initiates file‑system modifications and purges after confirming execution conditions. For Android, it exploits root privileges or leverages sideloaded APKs to wipe internal storage and user data; on Windows, the malware deletes registry entries, system services, and application files, accompanied by attempts to remove forensic evidence such as logs and remnants of its own code. The dual‑platform nature suggests an effort to maximize impact across different device ecosystems within the target networks. Beyond local destruction, preliminary reports indicate that SameCoin may log system information or exfiltrate basic metadata before wiping, potentially providing WIRTE with actionable intelligence regarding victim characteristics. Its presence in a broader campaign implies integration into automated attack frameworks featuring modular payload delivery and optional encryption to obscure command and control (C2) traffic.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The available information confirms SameCoin’s existence as a dual‑platform wiper used by WIRTE in Middle Eastern campaigns, yet specific indicators such as file hashes, command–control domains or detailed behavioral logs are not provided. Consequently, confidence is moderate regarding its destructive capabilities but low concerning precise attack vectors and detection signatures due to the absence of granular technical data.
SameCoin is a multi-platform wiper with Windows and Android versions that has been used by WIRTE to target entities in the Middle East including in Israel.(Citation: Check Point Wirte NOV 2024)