Also known as: Samas
Executive Summary
SamSam is a targeted Windows ransomware that relies on manual operator intervention for deployment and employs a two‑stage AES‑256 encryption process with victim‑specific keys. It has caused significant disruption among hospitals, insurers, and government agencies during 2017–2018. The malware communicates with its command‑and‑control servers over HTTP/HTTPS and requires administrative access to effectively encrypt files.
Enhanced Description
SamSam is a Windows‑targeted ransomware family that surfaced in early 2016 and gained widespread notoriety during the 2017–2018 outbreak against healthcare, industrial, and municipal organizations. Unlike many peer ransomware families that rely on automated delivery via exploit kits or phishing attachments, SamSam typically requires a human operator to upload and manually execute the payload on an infected host. Operators usually run the binary in a limited user context or through administrative privileges provided by the compromised account. Once executed, SamSam encrypts a wide range of file extensions (.docx, .xlsx, .pdf, .jpg, etc.) with AES‑256 using a unique public key for each victim. The encryption is performed in two stages: an initial local encryption followed by a second pass that ensures data integrity and resists recovery attempts. The private decryption key is held exclusively by the threat actors and never stored locally, compelling victims to contact the attackers and pay the ransom if they wish to recover their files. Operationally, SamSam communicates with a small set of command‑and‑control servers over HTTP or HTTPS on non‑standard ports. The malware does not exhibit lateral movement capabilities; instead, it focuses solely on data exfiltration via encrypted channels before shutting down the infected system or forcing a reboot after encryption completes. While it lacks widespread exploitation mechanisms, the manual nature of its distribution underscores that many infections began from compromised administrative accounts rather than zero‑day vulnerabilities.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on publicly documented incident reports from US‑CERT, Sophos, Talos, and Symantec which provide consistent details about SamSam’s manual deployment and encryption methodology. However, core metadata such as exact first/last sighting dates, complete list of file hashes, and comprehensive persistence mechanisms are missing, limiting deeper technical profiling. Confidence in the high‑level behaviors is moderate to high, while gaps remain around automation, lateral movement potential, and advanced evasion tactics.
SamSam is ransomware that appeared in early 2016. Unlike some ransomware, its variants have required operators to manually interact with the malware to execute some of its core components.(Citation: US-CERT SamSam 2018)(Citation: Talos SamSam Jan 2018)(Citation: Sophos SamSam Apr 2018)(Citation: Symantec SamSam Oct 2018)