Skip to content

Hide Navigation Hide TOC

SameCoin - S9030 (4e164a21-3fbe-4aaa-be69-2513fdba90f7)

SameCoin is a multi-platform wiper with Windows and Android versions that has been used by WIRTE to target entities in the Middle East including in Israel.(Citation: Check Point Wirte NOV 2024)

Cluster A Galaxy A Cluster B Galaxy B Level
Lateral Tool Transfer - T1570 (bf90d72c-c00b-45e3-b3aa-68560560d4c5) Attack Pattern SameCoin - S9030 (4e164a21-3fbe-4aaa-be69-2513fdba90f7) Malware 1
File and Directory Discovery - T1083 (7bc57495-ea59-4380-be31-a64af124ef18) Attack Pattern SameCoin - S9030 (4e164a21-3fbe-4aaa-be69-2513fdba90f7) Malware 1
Internal Spearphishing - T1534 (9e7452df-5144-4b6e-b04a-b66dd4016747) Attack Pattern SameCoin - S9030 (4e164a21-3fbe-4aaa-be69-2513fdba90f7) Malware 1
File and Directory Discovery - T1420 (cf28ca46-1fd3-46b4-b1f6-ec0b72361848) Attack Pattern SameCoin - S9030 (4e164a21-3fbe-4aaa-be69-2513fdba90f7) Malware 1
SameCoin - S9030 (4e164a21-3fbe-4aaa-be69-2513fdba90f7) Malware Data Destruction - T1485 (d45a3d09-b3cf-48f4-9f0f-f521ee5cb05c) Attack Pattern 1
SameCoin - S9030 (4e164a21-3fbe-4aaa-be69-2513fdba90f7) Malware System Location Discovery - T1614 (c877e33f-1df6-40d6-b1e7-ce70f16f4979) Attack Pattern 1
Selective Exclusion - T1679 (9b00925a-7c4b-4e53-bfc8-9a6a806fde03) Attack Pattern SameCoin - S9030 (4e164a21-3fbe-4aaa-be69-2513fdba90f7) Malware 1
Data Destruction - T1662 (9ef14445-6f35-4ed0-a042-5024f13a9242) Attack Pattern SameCoin - S9030 (4e164a21-3fbe-4aaa-be69-2513fdba90f7) Malware 1
SameCoin - S9030 (4e164a21-3fbe-4aaa-be69-2513fdba90f7) Malware Scheduled Task - T1053.005 (005a06c6-14bf-4118-afa0-ebcd8aebb0c9) Attack Pattern 1
SameCoin - S9030 (4e164a21-3fbe-4aaa-be69-2513fdba90f7) Malware Internal Defacement - T1491.001 (8c41090b-aa47-4331-986b-8c9a51a91103) Attack Pattern 1
SameCoin - S9030 (4e164a21-3fbe-4aaa-be69-2513fdba90f7) Malware Match Legitimate Resource Name or Location - T1036.005 (1c4e5d32-1fe9-4116-9d9d-59e3925bd6a2) Attack Pattern 1
Scheduled Task/Job - T1053 (35dd844a-b219-4e2b-a6bb-efa9a75995a9) Attack Pattern Scheduled Task - T1053.005 (005a06c6-14bf-4118-afa0-ebcd8aebb0c9) Attack Pattern 2
Defacement - T1491 (5909f20f-3c39-4795-be06-ef1ea40d350b) Attack Pattern Internal Defacement - T1491.001 (8c41090b-aa47-4331-986b-8c9a51a91103) Attack Pattern 2
Masquerading - T1036 (42e8de7b-37b2-4258-905a-6897815e58e0) Attack Pattern Match Legitimate Resource Name or Location - T1036.005 (1c4e5d32-1fe9-4116-9d9d-59e3925bd6a2) Attack Pattern 2