SameCoin

S9030

Malware.View on attack.mitre.org

About this malware

SameCoin is a multi-platform wiper with Windows and Android versions that has been used by WIRTE to target entities in the Middle East including in Israel.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1036.005
Match Legitimate Resource Name or Location

SameCoin has named files to appear legitimate such as "MicrosoftEdge.exe."

T1053.005
Scheduled Task

SameCoin has the ability to set a scheduled task for execution.

T1083
File and Directory Discovery

SameCoin can list all system files and can avoid wiping specific directories such as Program Files, Windows, and Users.

T1485
Data Destruction

SameCoin can overwrite designated files on targeted systems with random bytes.

T1491.001
Internal Defacement

SameCoin can alter the victim’s background to display an image showing the name of Hamas’s military wing.

T1534
Internal Spearphishing

SameCoin can send its Setup.exe file as an attachment to other addresses in the same compromised organization.

T1570
Lateral Tool Transfer

SameCoin can copy its wiper executable to remote machines within the same Active Directory.

T1614
System Location Discovery

SameCoin can attempt to connect to the Israel Home Front Command site, oref.org[.]il, which is only reachable from within Israel to verify the target's location.

T1679
Selective Exclusion

SameCoin can avoid overwriting file names that contain “desktop.ini” and “conf.conf."

Groups that use it1

Campaigns0

None recorded.

References1

  1. Check Point Wirte NOV 2024 Open source
    Check Point. (2024, November 12). Hamas-affiliated Threat Actor WIRTE Continues its Middle East Operations and Moves to Disruptive Activity. Retrieved April 20, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.