Threats Feed|Unclassified|Last Updated 15/07/2026|AuthorCertfa Radar|Publish Date03/12/2018

SamSam Ransomware Targets US Critical Infrastructure with RDP Exploits

  • Actor Motivations: Extortion,Financial Gain
  • Attack Vectors: Brute-force,Vulnerability Exploitation,Ransomware
  • Attack Complexity: Medium
  • Threat Risk: High Impact/High Probability

Threat Overview

The SamSam ransomware group exploited vulnerabilities in Windows servers and JBoss applications, predominantly targeting organizations in the United States, with victims also reported internationally. The group focused on critical infrastructure sectors and other industries, leveraging stolen Remote Desktop Protocol (RDP) credentials obtained from darknet marketplaces. Using brute force and exploitation techniques, SamSam actors gained persistent access, escalated privileges, deployed ransomware, and encrypted entire networks to demand Bitcoin ransoms. Victims received instructions via Tor for ransom payment and decryption. The rapid execution of attacks and the sale of stolen credentials often resulted in additional unauthorized activities on victim networks.

Detected Targets

TypeDescriptionConfidence
RegionUnited States
Verified

Extracted IOCs

  • anonyme[.]com
  • evilsecure9.wordpress[.]com
  • followsec7.wordpress[.]com
  • key88secu7.wordpress[.]com
  • keytwocode.wordpress[.]com
  • lordsecure4u.wordpress[.]com
  • payforsecure7.wordpress[.]com
  • secangel7d.wordpress[.]com
  • union83939k.wordpress[.]com
  • zeushelpu.wordpress[.]com
  • 01784b876d14b1384491318f8fce07d5
  • 02c19bbf8e19bb69fc7870ec872d355e
  • 06441ad348b483e2458a535949e809cf
  • 074e52525d5ec2b2af8675477180b5f0
  • 124120a6b861fdfff756e19a77a53e05
  • 12fe3b15c663fe9ed9480c352f9bded3
  • 14721036e16587594ad950d4f2db5f27
  • 1afc39b101a64c61b763fdf07fde1d55
  • 222d7fde37ae344824a97087d473cdcd
  • 37c3e95eb9901183e02df0ba1de6caf2
  • 397b763d106b2f347c5a563922273551
  • 5b168ad87a0de81c443656cc144df29a
  • 5e1317af9956be12deebdea49aae14f5
  • 62e21431e87e8a21cf06319da7438f11
  • 76bd79f774ae892fd6a30b6463050a91
  • 7a556f246357051b2d82ea445571ddbb
  • 816849886aa28e56db0cd065fae38897
  • 8a2d72fec9d2535440e0f83b59253f2b
  • 8ef9498de2781e9f674c2727ab3546c6
  • 9cf5eb0ba3d939001e41a98351a45be5
  • a14ea969014b1145382ffcd508d10156
  • ad25e96cae2016331129ec4643535822
  • b227291feae10a83e762c2bc9d959a7f
  • b85b73ffa6d2bc4679ee6ece174a93b1
  • b96620d8a08fa436ea22ef480dd883ce
  • d0b581056989efaa1de31a61a8f4a9ec
  • f702153b68628eff973abb2912af0d22
  • fe3ae84a8defc809e734bbd0736f82de
  • fe998080463665412b65850828bce41f
  • 04a2ea4c78f78d628800c0a5cb9547a0c0b14378
  • 138c3aae51e67db0c4134affae428fe91c0d1686
  • 203bb8ec1da6b237a092bab71fa090849c7db9bd
  • 4d7a60bd1fb3677a553f26d95430c107c8485129
  • 631e5f4b9a3ba6855dd93dbdccb416337560491d
  • 89fe55d2669e6c995b9a0d9ed5d5aa404d20713b
  • 90205a2761ed7ac3b188230786ec2bebd30effba
  • a1ab74d2f06a542e77ea2c6d641aae4ed163a2da
  • a4708853f4a7e4e242a236a433e9b5e8593f1090
  • c3cf36abda1463dbe81dc7a7283c6a089c922071
  • cc76586ef94122329e825c78aad2ecb9ac064343
  • ed1797c282f0817d2ad8f878f8dd50ab062501ac
  • ff2f511009b2813af9d12c6103206828560869db
  • ff6aa732320d21697024994944cf66f7c553c9cd
  • 036071786d7db553e2415ec2e71f3967baf51bdc31d0a640aa4afb87d3ce3050
  • 0f2c5c39494f15b7ee637ad5b6b5d00a3e2f407b4f27d140cd5a821ff08acfac
  • 2b06d2abc87f51aa7b8451da16270003ceba57184b0dd5f244670873409c75b9
  • 32445c921079aa3e26a376d70ef6550bafeb1f6b0b7037ef152553bb5dad116f
  • 427091e1888c2bf1f2e11a1010b3ab6c8634eda4ddc34d37202d401fbaa8989d
  • 45e00fe90c8aa8578fce2b305840e368d62578c77e352974da6b8f8bc895d75b
  • 553967d05b83364c6954d2b55b8cfc2ea3808a17c268b2eee49090e71976ba29
  • 58ef87523184d5df3ed1568397cea65b3f44df06c73eadeb5d90faebe4390e3e
  • 594b9b42a2d7ae71ef08795fca19d027135d86e82bc0d354d18bfd766ec2424c
  • 5d65ebdde1aef8f23114f95454287e7410965288f144d880ece2a2b8c3128645
  • 6245a51e78526c25510d0aa0909576119fdf0244619f670036538063b88f1c21
  • 6bc2aa391b8ef260e79b99409e44011874630c2631e4487e82b76e5cb0a49307
  • 738c95f5bfe63a530b200a0d73f363d46c5671c1fcbb69c217e15a3516501a86
  • 7aa585e6fd0a895c295c4bea2ddb071eed1e5775f437602b577a54eef7f61044
  • 89b4abb78970cd524dd887053d5bcd982534558efdf25c83f96e13b56b4ee805
  • 939efdc272e8636fd63c1b58c2eec94cf10299cd2de30c329bd5378b6bbbd1c8
  • 946dd4c4f3c78e7e4819a712c7fd6497722a3d616d33e3306a556a9dc99656f4
  • 979692a34201f9fc1e1c44654dc8074a82000946deedfdf6b8985827da992868
  • 97d27e1225b472a63c88ac9cfb813019b72598b9dd2d70fe93f324f7d034fb95
  • 9b23bfc35b18ed80104c496b2aa722b3e56ff9ceb9dae60d1aff7230321c1d12
  • a660cc6155b307c0957c4c6ea119a295a852d28097196d85f00f5517944a3dcb
  • a763ed678a52f77a7b75d55010124a8fccf1628eb4f7a815c6d635034227177e
  • bbd4102fe25e73c0815d0c020d60d47dbbfbe79ef1e490e7b4f97640dd932b58
  • bc53f513df363dd999ac855b53831b3b31ac5516a4bf8f324489710cf06955f0
  • d8d919d884b86e4d5977598bc9d637ed53e21d5964629d0427077e08ddbcba68
  • da9c2ecc88e092e3b8c13c6d1a71b968aa6f705eb5966370f21e306c26cd4fb5
  • e682ac6b874e0a6cfc5ff88798315b2cb822d165a7e6f72a5eb74e6da451e155
  • ffef0f1c2df157e9c2ee65a12d5b7b0f1301c4da22e7e7f3eac6b03c6487a626
  • 16d5cab293ffe44a8bfe247fc8f60167741d4a44cb12542b378cf26b689abcff95065ab44e4725b2ab3e85295925faa695bce1159d06211c1bf971d437398414
  • 177f25c2e454b5366719a5536e25dbf16ab5cb01b1886b18ea1477671651191cbf663cf1754990c618be1d7c36bf523aaac8528d94a1d49583213dc8a0dee98a
  • 283681b5b8e78440bf474c8e50504e6e82f25bd3f6240d5e70600e43fc9fd609a78ee7b837c9b68aa25ed13f2ee735f360a18e614ded15e11bb62043cd028c99
  • 2a9f4ebb025c8e7b4e074d301477656ffad66318da5ea35ddc8363c17f4bdbf501778539133261adbb9f441066a1e2b79240306ad1877f5ef17009c8f05ff4a6
  • 35b066679ce733b0de20b79cb7570570164eb695307cbb96173bd7c4485b62a42e5b67caab8b9373e45b9cd9abe72ab0eb78960256420144b9f609c3734320f0
  • 4d9e75850713f0bf6892fca8d74f462a5b2c0ccec2ed089fd830b8babcce7aedbd3bcb56e25c81cb6bf285bba9111ef89913d0c665593b2ba8da5f57d9505d32
  • 547efea0c2407d1e2949e84fe107820a1efaab2eaddeaf60ceb8f23b53d635b7c86ceadb1e19c07432e51a3609d02f12aca99cb5e23b5d324febb67994f83a9c
  • 67e0046db0b565a1ac1862bbd536016c3ea984f8fceadaa31b4c99e7a8b434b170d5badbb10c2c25e264b17bbf2f97576f252e7ef74279b3b845b1553cef9829
  • 73f28bed4ee700e15d1c0eb9871e37bdda77e3ef3c14b63a1597b9628e7407dc31f8382e0ec52c8c65f68c00a4f321f5971359f865eb35b35dc62e9f5e8e7be1
  • 7b5c3a6dcc30225874b70e9aa5df803d7796322e5c6654b0ace265b95b0134035384e113112a7a17b09e24dbceb71a22867424cfc1c660ec2ebb605583980dcd
  • 853eec13cba76de73361f1fb1e18d11ce3c1b9496f5e093d3050283643f569b659a5931b2092d8302cc8cfbfb69e4a6241461eed4c8931879818c4280af025cf
  • 9ade6edde3f063fc935f53366ffc9cb6cf7e17691d22fd2fe107d779da3b61eaed006ef7679b456bc16aca8b686d035f09aaf42bf06fa62b872e0a89046994eb
  • 9cb6ddb8a0b9329fe08fcf8a02d45c43222432d6e145f55deacb019f772970513d3ddfa589a002c0abf190fa8712d41e08aab51836685aed9bf30d118ea00a5e
  • f2f60c6eb6d96c025a34eb58e175866e15a806f9ec805793676cc60ede00dbfd55b9ade816c6148235e4fc34c4c412d91ae873d324032f1dbd17b09a7a539233
download

Tip: 95 related IOCs (0 IP, 10 domain, 0 URL, 0 email, 85 file hash) to this threat have been found.

Overlaps

UnclassifiedHospitals and Schools Under Siege: SamSam’s Targeted Ransomware Campaign

Source: Sophos - April 2018

Detection (three cases): 138c3aae51e67db0c4134affae428fe91c0d1686, 4d7a60bd1fb3677a553f26d95430c107c8485129, a1ab74d2f06a542e77ea2c6d641aae4ed163a2da

UnclassifiedSamSam Ransomware Exploits JBoss Servers, Targets Healthcare Sector

Source: Cisco - March 2016

Detection (14 cases): 036071786d7db553e2415ec2e71f3967baf51bdc31d0a640aa4afb87d3ce3050, 0f2c5c39494f15b7ee637ad5b6b5d00a3e2f407b4f27d140cd5a821ff08acfac, 45e00fe90c8aa8578fce2b305840e368d62578c77e352974da6b8f8bc895d75b, 553967d05b83364c6954d2b55b8cfc2ea3808a17c268b2eee49090e71976ba29, 58ef87523184d5df3ed1568397cea65b3f44df06c73eadeb5d90faebe4390e3e, 6bc2aa391b8ef260e79b99409e44011874630c2631e4487e82b76e5cb0a49307, 7aa585e6fd0a895c295c4bea2ddb071eed1e5775f437602b577a54eef7f61044, 89b4abb78970cd524dd887053d5bcd982534558efdf25c83f96e13b56b4ee805, 939efdc272e8636fd63c1b58c2eec94cf10299cd2de30c329bd5378b6bbbd1c8, 946dd4c4f3c78e7e4819a712c7fd6497722a3d616d33e3306a556a9dc99656f4, 979692a34201f9fc1e1c44654dc8074a82000946deedfdf6b8985827da992868, a763ed678a52f77a7b75d55010124a8fccf1628eb4f7a815c6d635034227177e, e682ac6b874e0a6cfc5ff88798315b2cb822d165a7e6f72a5eb74e6da451e155, ffef0f1c2df157e9c2ee65a12d5b7b0f1301c4da22e7e7f3eac6b03c6487a626

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

SamSam Ransomware Threat

The Department of Homeland Security (DHS) and the FBI have identified a ransomware threat known as SamSam (or MSIL/Samas.A). Attackers are breaking into corporate networks, taking control of systems, and encrypting computers to demand a ransom payment.

The attacks are carried out by a specific group of cyber actors tracked as the SamSam operators. They are known for their fast-moving, network-wide attacks and for purchasing stolen network credentials from illegal darknet marketplaces.

The primary goal is financial extortion. The attackers lock victims out of their own networks by encrypting their computers, then demand a ransom payment in Bitcoin via a hidden darkweb site in exchange for the tools to unlock the network.

The campaign operates on a broad scale, predominantly targeting organizations located in the United States, though international entities have also been impacted.

Yes, the attackers targeted multiple industries, with a specific focus on organizations within critical infrastructure. Instead of targeting individuals, they focus on compromising entire organizational networks to maximize the impact.

Historically, attackers exploited software vulnerabilities to get in. More recently, they have been logging directly into networks using stolen usernames and passwords or by guessing passwords for remote access services. Once inside, they silently spread the infection across the entire network without needing an employee to accidentally click a bad link or open a malicious email.

Organizations that provide critical or essential functions are highly attractive because they cannot afford prolonged downtime. Their urgent need to restore operations quickly makes them much more likely to pay larger ransom demands.

It is a targeted issue aimed at specific organizations rather than a widespread consumer threat. The attackers deliberately focus on corporate networks where they can maximize operational disruption and extract high ransom payments.

Organizations should focus on securing how their networks are accessed remotely, particularly focusing on Remote Desktop connections. This includes using strong passwords, monitoring access logs for unusual login activity, and ensuring all software applications are up to date to prevent attackers from sneaking in through known vulnerabilities.