SamSam Ransomware Exploits JBoss Servers, Targets Healthcare Sector
- Actor Motivations: Extortion,Financial Gain
- Attack Vectors: Vulnerability Exploitation,Malware,Ransomware
- Attack Complexity: Medium
- Threat Risk: High Impact/High Probability
Threat Overview
The SamSam ransomware campaign exploited vulnerabilities in public-facing JBoss application servers, leveraging JexBoss for initial access. The attackers gained a foothold, moved laterally across networks, and deployed SamSam ransomware to encrypt Windows systems. The healthcare sector was a primary target, with ransom demands increasing over time—from 1 BTC per system to 1.7 BTC. Attackers also introduced a bulk decryption option for 22 BTC. REGeorg's tunnel.jsp was used to maintain access. The malware employed Rijndael encryption with RSA-2048 key wrapping, rendering files unrecoverable without payment. The campaign demonstrated a shift from phishing to direct server exploitation, highlighting the evolving nature of ransomware attacks.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Healthcare | Verified |
| Region | United States | Verified |
Extracted IOCs
- 036071786d7db553e2415ec2e71f3967baf51bdc31d0a640aa4afb87d3ce3050
- 0f2c5c39494f15b7ee637ad5b6b5d00a3e2f407b4f27d140cd5a821ff08acfac
- 45e00fe90c8aa8578fce2b305840e368d62578c77e352974da6b8f8bc895d75b
- 553967d05b83364c6954d2b55b8cfc2ea3808a17c268b2eee49090e71976ba29
- 58ef87523184d5df3ed1568397cea65b3f44df06c73eadeb5d90faebe4390e3e
- 6bc2aa391b8ef260e79b99409e44011874630c2631e4487e82b76e5cb0a49307
- 7aa585e6fd0a895c295c4bea2ddb071eed1e5775f437602b577a54eef7f61044
- 89b4abb78970cd524dd887053d5bcd982534558efdf25c83f96e13b56b4ee805
- 939efdc272e8636fd63c1b58c2eec94cf10299cd2de30c329bd5378b6bbbd1c8
- 946dd4c4f3c78e7e4819a712c7fd6497722a3d616d33e3306a556a9dc99656f4
- 979692a34201f9fc1e1c44654dc8074a82000946deedfdf6b8985827da992868
- a763ed678a52f77a7b75d55010124a8fccf1628eb4f7a815c6d635034227177e
- b963b8b8c5ca14c792d2d3c8df31ee058de67108350a66a65e811fd00c9a340c
- e682ac6b874e0a6cfc5ff88798315b2cb822d165a7e6f72a5eb74e6da451e155
- ffef0f1c2df157e9c2ee65a12d5b7b0f1301c4da22e7e7f3eac6b03c6487a626
Tip: 15 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 15 file hash) to this threat have been found.
Overlaps
Source: CISA - December 2018
Detection (14 cases): 036071786d7db553e2415ec2e71f3967baf51bdc31d0a640aa4afb87d3ce3050, 0f2c5c39494f15b7ee637ad5b6b5d00a3e2f407b4f27d140cd5a821ff08acfac, 45e00fe90c8aa8578fce2b305840e368d62578c77e352974da6b8f8bc895d75b, 553967d05b83364c6954d2b55b8cfc2ea3808a17c268b2eee49090e71976ba29, 58ef87523184d5df3ed1568397cea65b3f44df06c73eadeb5d90faebe4390e3e, 6bc2aa391b8ef260e79b99409e44011874630c2631e4487e82b76e5cb0a49307, 7aa585e6fd0a895c295c4bea2ddb071eed1e5775f437602b577a54eef7f61044, 89b4abb78970cd524dd887053d5bcd982534558efdf25c83f96e13b56b4ee805, 939efdc272e8636fd63c1b58c2eec94cf10299cd2de30c329bd5378b6bbbd1c8, 946dd4c4f3c78e7e4819a712c7fd6497722a3d616d33e3306a556a9dc99656f4, 979692a34201f9fc1e1c44654dc8074a82000946deedfdf6b8985827da992868, a763ed678a52f77a7b75d55010124a8fccf1628eb4f7a815c6d635034227177e, e682ac6b874e0a6cfc5ff88798315b2cb822d165a7e6f72a5eb74e6da451e155, ffef0f1c2df157e9c2ee65a12d5b7b0f1301c4da22e7e7f3eac6b03c6487a626
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
SamSam Ransomware Campaign
A widespread cybersecurity campaign is currently compromising organizational networks using a specific type of malicious software known as SamSam ransomware. The attackers are breaking into vulnerable web servers and moving through the internal network to lock up multiple computers, holding the files hostage for a ransom payment.
While the specific identities of the individuals are not detailed in the report, they are financially motivated cybercriminals. They are known for leveraging publicly available, open-source hacking tools to conduct their network intrusions rather than building their own custom access malware.
The primary goal of this campaign is financial extortion. The attackers lock victims out of their own data using strong encryption and demand payment in Bitcoin to provide the recovery keys, offering both individual computer unlocking and bulk network unlocking options.
Yes, while this is a widespread campaign affecting multiple entities, the attackers have placed a deliberate and particular focus on targeting organizations within the healthcare industry.
Instead of tricking employees with fake emails, the attackers directly exploit vulnerable public-facing servers to force their way into a network. Once inside, they manually spread the ransomware to as many internal Windows computers as possible, launching the encryption process without generating suspicious network traffic back to the attackers.
Organizations like those in the healthcare industry rely heavily on constant access to their systems and data to function. This operational urgency makes them highly vulnerable to network-wide disruptions, increasing the likelihood that they will pay the demanded ransom to restore critical services quickly.