SamSam — Ransomware Profile

SamSam is a hands-on-keyboard ransomware family deployed in targeted intrusions, and its variants have required operators to manually interact with the malware to execute some of its core components. Secureworks' Counter Threat Unit began tracking the financially motivated campaigns in late 2015 and associates the activity with the threat group it designates GOLD LOWELL. Between late 2015 and mid-2016, many of the group's network intrusions used the JexBoss tool to compromise vulnerable internet-facing JBoss systems; Red Hat reported CVE-2010-0738 as the main flaw it saw exploited, with unsecured consoles the main route in. In January 2017 the group began targeting legitimate RDP account credentials, in some cases compromising accounts by brute force, and FBI analysis of victim access logs found the actors can infect a network within hours of purchasing credentials, escalating privileges for administrator rights before dropping and running the malware on the server. Symantec's October 2018 reporting found evidence of attacks against 67 organisations during 2018, 56 of them in the United States, with healthcare by far the worst-hit sector at 24 percent of attacks. The US Treasury put the scheme's toll at over 200 known victims and in November 2018 sanctioned two Iran-based individuals under Executive Order 13694 for exchanging the bitcoin ransoms into Iranian rial on behalf of the Iranian malicious cyber actors involved with the SamSam ransomware scheme.

Also tracked as

Samas, MSIL/Samas.A, GOLD LOWELL, Ransom.SamSam

Vendor research

Read the full analysis on IntelFusions