SamSam Ransomware Evolves, Nets Over $325K in Four Weeks
- Actor Motivations: Extortion,Financial Gain
- Attack Vectors: Ransomware
- Attack Complexity: Medium
- Threat Risk: High Impact/High Probability
Threat Overview
A new variant of the SamSam ransomware has netted over $325,000 in four weeks, targeting government, healthcare, and industrial control systems (ICS). The attacks are opportunistic, with potential initial access through compromised RDP/VNC servers. The ransomware is deployed manually, encrypting files using DES and AES encryption. New anti-analysis techniques, including string obfuscation and a loader-based deployment mechanism ("Runner"), make detection more challenging. Unlike most ransomware, SamSam does not delete Volume Shadow Copies, allowing possible file recovery. The campaign uses hardcoded Tor addresses and Bitcoin wallets for ransom transactions, with payments being tracked on the blockchain. The US and other regions are likely affected, given past SamSam activity.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Government Agencies and Services | Verified |
| Sector | Healthcare | Verified |
| Region | United States | Verified |
Extracted IOCs
- jcmi5n4c3mvgtyt5[.]onion
- 0785bb93fdb219ea8cb1673de1166bea839da8ba6d7312284d2a08bd41e38cb9
- 338fdf3626aa4a48a5972f291aacf3d6172dd920fe16ac4da4dd6c5b999d2f13
- 3531bb1077c64840b9c95c45d382448abffa4f386ad88e125c96a38166832252
- 4856f898cd27fd2fed1ea33b4d463a6ae89a9ccee49b134ea8b5492cb447fb75
- 516fb821ee6c19cf2873e637c21be7603e7a39720c7d6d71a8c19d8d717a2495
- 72832db9b951663b8f322778440b8720ea95cde0349a1d26477edd95b3915479
- 754fab056e0319408227ad07670b77dde2414597ff5e154856ecae5e14415e1a
- 88d24b497cfeb47ec6719752f2af00c802c38e7d4b5d526311d552c6d5f4ad34
- 88e344977bf6451e15fe202d65471a5f75d22370050fe6ba4dfa2c2d0fae7828
- 8eabfa74d88e439cfca9ccabd0ee34422892d8e58331a63bea94a7c4140cf7ab
- 8f803b66f6c6bc4da9211a2c4c4c5b46a113201ecaf056d35cad325ec4054656
- dabc0f171b55f4aff88f32871374bf09da83668e1db2d2c18b0cd58ed04f0707
- e7bebd1b1419f42293732c70095f35c8310fa3afee55f1df68d4fe6bbee5397e
Tip: 14 related IOCs (0 IP, 1 domain, 0 URL, 0 email, 13 file hash) to this threat have been found.
Overlaps
Source: Sophos - April 2018
Detection (one case): jcmi5n4c3mvgtyt5[.]onion
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
SamSam Ransomware Variant
A new variant of the SamSam ransomware is actively infecting organizational networks. Once inside, it encrypts critical files and demands a cryptocurrency ransom to restore access, successfully extracting over $325,000 from victims within a four-week period.
The specific identities of the threat actors are unknown, but they are utilizing the SamSam malware family. These attackers are known for their highly manual operations, meaning they actively navigate a victim's network by hand rather than relying on automated spreading mechanisms.
The primary goal of the attack is financial extortion. By locking victims out of their own data and operational systems, the attackers demand Bitcoin in exchange for the decryption keys needed to regain access.
These attacks are widespread and opportunistic in nature, rather than being highly targeted at specific organizations. The threat actors appear to infect vulnerable systems wherever they find them, scanning for easy footholds to exploit.
While not exclusively targeted, the Government, Healthcare, and Industrial Control Systems (ICS) sectors have been heavily impacted. The effect on healthcare is particularly severe, as the ransomware can freeze highly computerized, life-saving medical devices and block access to critical patient histories.
Attackers likely break into a network through remote access tools and manually move across the system. They then launch a "loader" program that unlocks and executes the ransomware, which sifts through the hard drive and encrypts important files while carefully leaving the core operating system intact.
Organizations in healthcare and government rely heavily on constant uptime to function and save lives. Because the attackers intentionally leave the computers bootable, desperate organizations are more likely to quickly pay the ransom to restore their vital systems.
Organizations should heavily secure and monitor remote access points to prevent attackers from gaining an initial foothold. If already infected, victims might be able to recover their data using the operating system's built-in backup features, as this specific ransomware variant does not destroy them.
This is a widespread, opportunistic threat. The attackers are casting a wide net across multiple industries, successfully impacting any vulnerable organization they can infiltrate.