SameCoin is a custom destructive malware family used in targeted attacks against Israeli organizations in 2024. It is best characterized as a wiper, with observed campaigns in February and October 2024 culminating in file destruction rather than monetization. Reporting links SameCoin to WIRTE, a Hamas-affiliated threat actor associated with the Gaza Cybergang/TA402 cluster, marking an evolution in that actor’s operations from primarily regional espionage toward combined espionage-and-sabotage activity.
Observed SameCoin campaigns relied on phishing-themed lures and impersonation of trusted entities to reach victims. In one documented wave, emails impersonating a legitimate Israeli ESET reseller targeted organizations including hospitals and municipalities. The malware was also described as using Israel-specific victim validation logic before activation, indicating deliberate geofencing and target discrimination. Components associated with the October 2024 variant included an infector element capable of spreading within an organization through Outlook attachments and Active Directory scheduled-task abuse, alongside the destructive payload.
The core destructive behavior consists of overwriting files outside protected directories with random data. SameCoin has been described as having Windows and Android variants, indicating a multi-platform family, although the best-documented destructive workflow is on Windows. Researchers also reported code-level overlap between SameCoin and newer WIRTE tooling, including shared encryption or XOR functionality, supporting an assessment of common development or direct operational linkage.
SameCoin fits into a broader pattern of politically motivated disruptive operations tied to the Israel-Hamas conflict, where the responsible actor combined phishing, DLL sideloading, custom loaders, post-exploitation tooling, and destructive payloads. Its use against healthcare and municipal targets in Israel underscores an intent to cause operational disruption and psychological impact in addition to any intelligence value gained earlier in the intrusion lifecycle.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2024, however, Check Point observed WIRTE employing SameCoin, a custom wiper malware, to attack Israeli entities in February and October.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a recently discovered wiper.
Destructive wiper used in WIRTE-linked operations (including activity branded as 'Cyber Toufan Al-Aqsa').
Destructive wiper malware used in WIRTE-linked operations (including activity associated with 'Cyber Toufan Al-Aqsa').
SameCoin is a custom wiper malware used by the WIRTE/APT group for destructive attacks, particularly targeting Israeli entities, to destroy data as part of sabotage operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.