Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareUsed by 1 actor

SameCoin

SameCoin is a custom wiper malware used by the Hamas-affiliated WIRTE threat actor in destructive attacks against Israeli entities. Check Point reported two 2024 waves, in February and October, and assessed clear links between SameCoin and WIRTE malware development. The malware was used in campaigns targeting Israeli organizations, including hospitals and municipalities, and one October 2024 campaign impersonated a legitimate Israeli ESET reseller. SameCoin is described as multi-platform, with Windows and Android variants.

In the October 2024 activity, a ZIP archive named ESETUnleashed_081024.zip contained legitimate DLLs and a malicious Setup.exe that deployed a newer SameCoin variant. The malware attempted to connect to oref.org.il and used the first bytes of the response as an XOR key to verify that the victim was in Israel before proceeding. Components included MicrosoftEdge.exe, identified as the wiper, and csrs.exe, identified as an infector capable of spreading within organizations via Outlook attachments and Active Directory scheduled tasks. The wiper overwrote files outside protected directories with random bytes, excluding filenames containing "desktop.ini" or "conf.conf."

Reporting also states that a February 24 campaign impersonated the Israeli National Cyber Directorate (INCD). In broader WIRTE operations, SameCoin is associated with a shift from espionage toward sabotage, while WIRTE continued parallel espionage campaigns across the Middle East. Check Point noted code overlap between the SameCoin wiper component and newer WIRTE loader variants, specifically a shared XOR/encryption function, supporting common development. Mentioned indicators and related artifacts include ESETUnleashed_081024.zip, MicrosoftEdge.exe, csrs.exe, and the geofencing/check target oref.org.il.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Molerats

In 2024, however, Check Point observed WIRTE employing SameCoin, a custom wiper malware, to attack Israeli entities in February and October.

via security online infosecurityonline.info
MITRE ATT&CK

Techniques & procedures

5 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence1

WIRTE’s campaigns leverage carefully crafted lures tailored to regional issues, often presented through malicious PDF files and archives.

T1566.001Spearphishing AttachmentEvidence1

A recent infection chain involved a PDF titled Developments of the War in Lebanon which led users to a RAR file containing DLL files used to deliver malicious payloads.

Execution

1 technique
T1053.005Scheduled TaskEvidence1

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.

Persistence

1 technique
T1053.005Scheduled TaskEvidence1

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.

Privilege Escalation

1 technique
T1053.005Scheduled TaskEvidence1

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.

Stealth

1 technique
T1497.001System ChecksEvidence1

The malware, designed to activate only in Israeli environments, “uses the first bytes of the response as its XOR key” to verify Israeli targets.

Discovery

1 technique
T1497.001System ChecksEvidence1

The malware, designed to activate only in Israeli environments, “uses the first bytes of the response as its XOR key” to verify Israeli targets.

Impact

1 technique
T1561Disk WipeEvidence1

In 2024, however, Check Point observed WIRTE employing SameCoin, a custom wiper malware, to attack Israeli entities in February and October.

INDICATORS OF COMPROMISE

IOCs tracked for this family

1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app2 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching1

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping5

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.