SamSam

Malware updated 4 months ago (2024-05-04T18:48:38.150Z)
Download STIX
Preview STIX
SamSam is a type of malware, specifically ransomware, that was first deployed by the cybercriminal group GOLD LOWELL in 2015. This malicious software is designed to infiltrate systems through suspicious downloads, emails, or websites and then exploit the compromised system, often stealing personal information, disrupting operations, or holding data hostage for ransom. Notably, SamSam is used in post-intrusion attacks, meaning it's deployed after an initial breach has occurred. This strategy was a novel approach at the time, marking a shift in the tactics employed by cybercriminals. The SamSam ransomware gained significant attention following high-profile attacks in 2018 against the city of Atlanta and the Colorado Department of Transportation (CDOT). In the Atlanta case, the attack caused substantial disruption to the city's IT infrastructure. Meanwhile, the CDOT attack led the state to declare a state of emergency and spend $1.7 million on recovery efforts. According to a 2018 report by Sophos, the SamSam ransomware had generated around $6 million in ransom payments since its creation. In response to these incidents and the growing threat of ransomware, the Office of Foreign Assets Control (OFAC) of the US Department of the Treasury issued its first crypto-related sanctions in 2018. These sanctions targeted two Iranian nationals associated with the SamSam ransomware campaign. The US has continued to sanction individuals involved in ransomware operations, including those associated with other notorious ransomware such as CryptoLocker, WannaCry, Evil Corp, REvil, and BlackShadow/Pay2Key. Despite these measures, ransomware remains a significant cybersecurity threat, with Remote Desktop Protocol (RDP) becoming a favored infection vector for ransomware criminals.
Description last updated: 2024-05-04T16:48:54.538Z
What's your take? (Question 1 of 0)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Ransomware
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the SamSam Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Recorded Future
7 months ago
What is the Cyber Kill Chain? Phases and Process Explained
CERT-EU
8 months ago
Examples of Past and Current Attacks | #ransomware | #cybercrime | National Cyber Security Consulting
CERT-EU
a year ago
Crypto Market Saw Nearly $70B Worth of Illicit Transactions in Five Years – Global Security Mag Online
CERT-EU
a year ago
US and UK sanction 11 TrickBot and Conti cybercrime gang members
CERT-EU
a year ago
Cybersecurity in the U.S. Construction Industry: Navigating Challenges and Strategies for a Secure Future – Part 1
CERT-EU
a year ago
No Password Required: Threat Researcher at Cisco Talos and a Veteran of the Highest-Profile Cyber Incidents Who Roasts His Own Coffee Beans
CERT-EU
a year ago
SOC First Defense - Understanding The Cyber Attack Chain - A Defense with/without SOC
MITRE
2 years ago
Credential Stealing Malware | Mandiant Research
MITRE
2 years ago
SamSam - The Evolution Continues Netting Over $325,000 in 4 Weeks
MITRE
2 years ago
SamSam Ransomware | CISA
MITRE
2 years ago
SamSam: Targeted Ransomware Attacks Continue
MITRE
2 years ago
New Ransomware Variant "Nyetya" Compromises Systems Worldwide
Secureworks
2 years ago
Ransomware Evolution
GovCERT CH
2 years ago
Severe Ransomware Attacks Against Swiss SMEs
Malwarebytes
2 years ago
French law to report cyberincidents within 3 days to become effective soon
CERT-EU
2 years ago
Cyberattacks on Industrial Control Systems Jumped in 2022
CERT-EU
2 years ago
6 Best Ransomware Recovery Services for 2023 | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware - National Cyber Security Consulting
Malwarebytes
a year ago
Why we should be more open about ransomware attacks