Hospitals and Schools Under Siege: SamSam’s Targeted Ransomware Campaign
- Actor Motivations: Extortion,Financial Gain
- Attack Vectors: Brute-force,Vulnerability Exploitation,Ransomware
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
SamSam ransomware selectively targets organizations likely to pay ransom, such as hospitals and schools. Unlike indiscriminate ransomware campaigns, attackers exploit vulnerabilities or use brute-force attacks on weak RDP credentials to gain initial access. After infection, SamSam spreads laterally by network mapping and credential theft, deploying ransomware manually via PSEXEC and batch scripts. The malware executes through a runner component, decrypting the payload using a separate DLL. Attackers erase forensic traces by deleting execution-related files. Victims can pay per host or a total sum for decryption. SamSam has generated significant profits in Bitcoin payments, shifting wallet addresses over time to evade tracking.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Education Schools and educational institutions explicitly named as deliberate targets in Sophos reporting. | Verified |
| Sector | Healthcare Hospitals explicitly named as primary targets; SamSam disrupted healthcare operations to maximize ransom pressure. | Verified |
| Region | United States | Verified |
Extracted IOCs
- jcmi5n4c3mvgtyt5[.]onion
- 138c3aae51e67db0c4134affae428fe91c0d1686
- 3cbddf5f027b19e55366ecc0fd287f31379175a0
- 4d7a60bd1fb3677a553f26d95430c107c8485129
- 6b21aec23a844e6a5af1879c41b9632a0e705bb7
- 713973f14ae8ff88a63a1491e82e48f362e3aed7
- a1ab74d2f06a542e77ea2c6d641aae4ed163a2da
- hxxp://jcmi5n4c3mvgtyt5[.]onion
Tip: 8 related IOCs (0 IP, 1 domain, 1 URL, 0 email, 6 file hash) to this threat have been found.
Overlaps
Source: CISA - December 2018
Detection (three cases): 138c3aae51e67db0c4134affae428fe91c0d1686, 4d7a60bd1fb3677a553f26d95430c107c8485129, a1ab74d2f06a542e77ea2c6d641aae4ed163a2da
Source: Cisco - January 2018
Detection (one case): jcmi5n4c3mvgtyt5[.]onion
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions
SamSam is ransomware that was used in a sustained campaign from 2016 through 2018, targeting organizations in the United States — primarily hospitals, schools, and government agencies. Unlike most ransomware of the era, it was deployed manually by human operators who first broke into a network, explored it, and then deliberately encrypted as many systems as possible before demanding payment. This made it far more damaging than automated ransomware campaigns.
The US Department of Justice indicted two Iranian nationals — Faramarz Shahi Savandi and Mohammad Mehdi Shah Mansouri — in November 2018 for conducting the SamSam attacks. No state sponsorship was established; the attacks appear to have been financially motivated criminal activity. The indictment did not result in arrests, as both individuals remained outside US jurisdiction.
The goal was financial. The attackers targeted organizations that were likely to pay quickly to restore operations — hospitals that couldn't afford downtime, schools with limited IT resources, and city governments with operational dependencies on their systems. Victims were given the option to pay per-encrypted machine or a flat rate for full network decryption, all in Bitcoin. The campaign generated significant ransom income across multiple years of operation.
SamSam targeted organizations across the United States. Confirmed victim categories include hospitals and healthcare providers, school districts, and municipal governments — most notably the City of Atlanta. The attackers focused on US-based targets throughout the campaign, selecting victims based on their perceived likelihood to pay and the operational damage a ransomware attack would cause.
The attackers got in one of two ways: by exploiting known vulnerabilities in internet-facing application servers (such as unpatched JBoss servers), or by brute-forcing weak passwords on Remote Desktop Protocol (RDP) connections that were exposed to the internet. Once inside, they manually explored the network, harvested credentials, and used a legitimate Windows administration tool called PsExec to push the ransomware to every machine they could reach — maximizing the damage before demanding payment.
SamSam stood out because it was operated by humans, not automated. Most ransomware of the time spread itself indiscriminately. SamSam operators instead behaved like skilled intruders: they entered quietly, took time to understand the target network, moved laterally to reach as many systems as possible, and only triggered the encryption when they were ready to cause maximum damage. They also kept the ransomware payload encrypted on disk until execution and deleted evidence afterward — making it harder for security teams to analyze or recover from.
Hospitals, schools, and government agencies were attractive because they tend to have older or under-maintained IT infrastructure, limited cybersecurity resources, and a strong operational need to restore systems quickly. A hospital that can't access patient records or critical systems faces immediate pressure to pay. Schools and city governments face similar public-service disruptions. The attackers understood this and deliberately chose victims where the cost of downtime exceeded the ransom demand.
Organizations should immediately disable or restrict internet-facing RDP — require MFA and limit access to known IPs. Internet-facing application servers must be patched quickly, particularly any running JBoss or similar platforms. Network segmentation is critical: limit how far any single compromised account can reach using PsExec or SMB. Maintain offline or immutable backups that ransomware cannot encrypt. Monitor for PsExec usage and unusual bulk file activity, which are signs of an active ransomware deployment in progress.