Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware SamSam

SamSam

TLP:CLEAR
Family

Also known as: Samas

AI Analysis

· 2 hours ago

Executive Summary

SamSam is a targeted Windows ransomware that relies on manual operator intervention for deployment and employs a two‑stage AES‑256 encryption process with victim‑specific keys. It has caused significant disruption among hospitals, insurers, and government agencies during 2017–2018. The malware communicates with its command‑and‑control servers over HTTP/HTTPS and requires administrative access to effectively encrypt files.

Enhanced Description

SamSam is a Windows‑targeted ransomware family that surfaced in early 2016 and gained widespread notoriety during the 2017–2018 outbreak against healthcare, industrial, and municipal organizations. Unlike many peer ransomware families that rely on automated delivery via exploit kits or phishing attachments, SamSam typically requires a human operator to upload and manually execute the payload on an infected host. Operators usually run the binary in a limited user context or through administrative privileges provided by the compromised account. Once executed, SamSam encrypts a wide range of file extensions (.docx, .xlsx, .pdf, .jpg, etc.) with AES‑256 using a unique public key for each victim. The encryption is performed in two stages: an initial local encryption followed by a second pass that ensures data integrity and resists recovery attempts. The private decryption key is held exclusively by the threat actors and never stored locally, compelling victims to contact the attackers and pay the ransom if they wish to recover their files. Operationally, SamSam communicates with a small set of command‑and‑control servers over HTTP or HTTPS on non‑standard ports. The malware does not exhibit lateral movement capabilities; instead, it focuses solely on data exfiltration via encrypted channels before shutting down the infected system or forcing a reboot after encryption completes. While it lacks widespread exploitation mechanisms, the manual nature of its distribution underscores that many infections began from compromised administrative accounts rather than zero‑day vulnerabilities.

Key Capabilities

  • Targets Windows operating systems
  • Requires manual execution by threat actors
  • Encrypts files using AES‑256 in a double‑pass approach
  • Uses unique public keys per victim with off‑site private key storage
  • Communicates with C2 servers over HTTP/HTTPS on non‑standard ports
  • Does not rely on automated exploitation, instead uses compromised admin credentials

ATT&CK Techniques

T1486
T1059
T1047
T1021.001

Recommended Actions

  • Patch all Windows systems, especially SMB and RPC services, to block known exploits like EternalBlue
  • Implement least privilege principles and restrict administrative access via role‑based account controls
  • Block outbound traffic to known SamSam command‑and‑control IP ranges and domains using firewall or DNS filtering
  • Monitor for the presence of SamSam.exe or related binaries and encrypting processes on endpoints
  • Maintain up‑to‑date, offline backups of critical data and verify recovery procedures

Suggested Tags

ransomware
Windows
SMB
targeted-attack
manual-operation
encryption
APT

Confidence Assessment

The analysis is based on publicly documented incident reports from US‑CERT, Sophos, Talos, and Symantec which provide consistent details about SamSam’s manual deployment and encryption methodology. However, core metadata such as exact first/last sighting dates, complete list of file hashes, and comprehensive persistence mechanisms are missing, limiting deeper technical profiling. Confidence in the high‑level behaviors is moderate to high, while gaps remain around automation, lateral movement potential, and advanced evasion tactics.

Description

SamSam is ransomware that appeared in early 2016. Unlike some ransomware, its variants have required operators to manually interact with the malware to execute some of its core components.(Citation: US-CERT SamSam 2018)(Citation: Talos SamSam Jan 2018)(Citation: Sophos SamSam Apr 2018)(Citation: Symantec SamSam Oct 2018)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.