Threats Feed|Unclassified|Last Updated 18/05/2026|AuthorCertfa Radar|Publish Date30/10/2018

SamSam Ransomware: Targeted Attacks Disrupt U.S. Healthcare and Government

  • Actor Motivations: Extortion,Financial Gain
  • Attack Vectors: Brute-force,Vulnerability Exploitation,Ransomware
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

Symantec's October 2018 analysis documented 67 confirmed SamSam targets during 2018, with 56 located in the United States. Healthcare was the single most affected sector, accounting for 24 percent of attacks, followed by local government organizations — at least one of which was involved in election administration. The group's most high-profile attack hit the City of Atlanta in March 2018, causing cleanup costs estimated at over $10 million; an attack on the Colorado Department of Transportation resulted in an additional $1.5 million in remediation costs. A November 2018 update confirmed that a US DOJ indictment of two Iranian nationals placed total ransom received at $6 million and damages to victims at over $30 million. SamSam operators employed "living off the land" tactics throughout — using legitimate administrative tools including PsExec, PsInfo, and Mimikatz rather than custom malware for reconnaissance, credential theft, and lateral movement. A documented February 2018 attack showed more than 48 hours elapsed between initial intrusion and encryption, during which the attackers mapped the network, harvested credentials, and staged two SamSam variants before encrypting nearly 250 computers in a single five-hour window. Outside the US, a small number of attacks were confirmed in Portugal, France, Australia, Ireland, and Israel.

Detected Targets

TypeDescriptionConfidence
CaseCity of Atlanta
Atlanta municipality. City of Atlanta has been targeted by Unclassified as the main target.
Verified
SectorGovernment Agencies and Services
Multiple local government organizations targeted including City of Atlanta and at least one election-administering entity.
Verified
SectorHealthcare
Healthcare was the single most affected sector, accounting for 24% of 2018 attacks per Symantec.
Verified
RegionAustralia
Small number of attacks confirmed in Australia per Symantec 2018 report.
Medium
RegionAustria
Verified
RegionFrance
Verified
RegionIreland
Verified
RegionIsrael
Verified
RegionPortugal
Verified
RegionUnited States
Verified

FAQs

Frequently Asked Questions

In 2018, the SamSam ransomware group carried out targeted attacks against 67 organizations, 56 of them in the United States. The attacks were notable for their precision and patience — operators would break into a network, spend days silently mapping it and stealing credentials, then encrypt as many machines as possible in a single coordinated push. The most damaging attack hit the City of Atlanta in March 2018, taking down municipal systems and costing over $10 million to remediate.

In November 2018, the US Department of Justice indicted two Iranian nationals — Faramarz Shahi Savandi and Mohammad Mehdi Shah Mansouri — for conducting the SamSam attacks. The FBI estimated they had collected $6 million in Bitcoin ransom payments and caused over $30 million in losses to victims. No state sponsorship was established; the attacks are assessed as financially motivated criminal activity. Neither individual was arrested, as both remained outside US jurisdiction.

The motivation was financial extortion. Victims were offered two payment options: pay per encrypted machine at a lower rate, or pay a flat sum to decrypt the entire network. Ransom demands frequently ran into tens of thousands of dollars. The attackers deliberately targeted organizations where the cost of operational downtime — lost patient records, disrupted government services, inaccessible city systems — would make paying the ransom feel more practical than rebuilding from scratch.

Healthcare organizations were the most frequently targeted, making up 24 percent of 2018 attacks. Local government was the second most affected category, with the City of Atlanta and Colorado Department of Transportation among confirmed victims — as well as at least one organization involved in election administration. The vast majority of targets were in the United States, with a small number of attacks in Portugal, France, Australia, Ireland, and Israel.

The attackers gained initial access through RDP brute-force attacks or exploitation of vulnerable internet-facing applications. Once inside, they used only legitimate Windows administration tools — PsInfo to map the network and identify valuable systems, Mimikatz to steal passwords, and PsExec to push the ransomware to remote machines. In one documented case, over 48 hours passed between first intrusion and encryption, during which the attackers worked quietly before encrypting nearly 250 computers in a five-hour window just after 5 a.m.

SamSam used only tools that already exist on Windows systems or are widely used by IT administrators — PsExec, PsInfo, and Mimikatz. This "living off the land" approach meant their activity looked like normal administrative work on network logs, making it extremely difficult for security tools to raise alerts. The same techniques are typically associated with sophisticated nation-state espionage groups, not financially motivated criminal actors — which is part of what made SamSam so effective and damaging.

Healthcare and government organizations tend to run complex, interconnected networks with older infrastructure and limited security resources. Hospitals in particular face immediate pressure to restore systems — patient care can't wait. Government agencies face public accountability and operational obligations that make prolonged outages untenable. The attackers understood this pressure and sized ransom demands to be painful but plausibly payable — making the economics of capitulating feel more attractive than weeks of recovery.

Restrict RDP to approved IP ranges and enforce MFA on all remote access services. Monitor for off-hours use of PsExec, PsInfo, and Mimikatz — these tools have legitimate uses but should rarely be running across a network at 5 a.m. Segment networks so a compromised machine cannot reach all others via SMB or admin shares. Maintain offline, immutable backups — networked backups are at risk of being encrypted too. Patch internet-facing services promptly, especially RDP and application servers. Finally, define and test an incident response plan before an attack occurs, not during one.