SamSam Ransomware

Description Summary

SamSam (a.k.a. Samas) was a targeted, manually-operated ransomware active from late 2015 to 2018. Rather than mass distribution, operators broke in via vulnerable JBoss servers and, later, brute-forced or stolen RDP credentials, then deployed the ransomware network-wide. It crippled the City of Atlanta, the Colorado Department of Transportation, and numerous hospitals. In November 2018 the U.S. DOJ indicted two Iranian nationals, attributing over USD 30 million in losses across 200+ victims.

Threat Actor

Two Iranian nationals (Faramarz Shahi Savandi, Mohammad Mehdi Shah Mansouri) indicted by the U.S. DOJ in 2018. Manual, targeted intrusions.

Technical Indicators

Encryption Extension
.encrypted / variant-specific (e.g. .weapologize, .keyxml)
Encryption Algorithm
AES (files) + RSA (key wrapping)
Ransom Note Name
'sorry'-themed HTML notes (e.g. HELP_DECRYPT_YOUR_FILES.html / 000-SORRY-FOR-FILES.html)
Targeted Industries
Government, Healthcare, Education, Transportation
First Seen
Late 2015 / January 2016
Last Seen
2018 (DOJ indictment)
Geographical Location
United States, Canada, United Kingdom

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 3 T1190 Exploit Public-Facing Application (JBoss)
T1133 External Remote Services (RDP)
T1078 Valid Accounts
Credential Access x 1 T1110 Brute Force
Execution x 1 T1059.001 PowerShell
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery