Samecoin

Malware updated 16 hours ago (2024-11-20T17:37:49.487Z)
Download STIX
Preview STIX
SameCoin is a multi-platform wiper malware, with versions for Android and Windows, identified in two significant waves of cyberattacks targeting Israeli entities in February and October 2024. The malware was often disguised as an Israeli National Cyber Directorate (INCD) security update, tricking users into unknowingly infecting their systems. It was deployed through suspicious downloads, emails, or websites, and once inside the system, it disrupted operations, possibly stealing personal information or holding data hostage. Notably, the most recent version of SameCoin altered the victim's background to display an image bearing the name of Hamas's military wing, the Al-Qassam Brigades. The malware was first reported by ESET, a cybersecurity company, which later released a newer version of the SameCoin wiper. This updated wiper was used in a malicious campaign impersonating the INCD on February 24. The campaign involved a specially crafted email containing a newly created version of the SameCoin Wiper, which was also deployed in attacks against Israel earlier that year. Researchers have identified clear links between the custom malware used by the group behind these attacks and SameCoin, according to analysis from HarfangLab. Unique code overlaps were found between the group's custom malware and SameCoin, further cementing the connection. The disruptive operations associated with SameCoin and another entity, WIRTE, are believed to be linked, indicating a potentially broader threat landscape.
Description last updated: 2024-11-15T15:54:35.049Z
What's your take? (Question 1 of 2)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Wiper
Hamas
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
Alias DescriptionAssociation TypeVotes
The WIRTE Threat Actor is associated with Samecoin. WIRTE is a threat actor that has been identified as part of several overlapping groups, including TA402, Molerats, and Frankenstein. In mid-2023, Proofpoint researchers first noticed WIRTE's activity within TA402, which targeted Middle Eastern governments using an intricate infection chain and a newUnspecified
2
Source Document References
Information about the Samecoin Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more