Description Summary
SamSam (a.k.a. Samas) was a targeted, manually-operated ransomware active from late 2015 to 2018. Rather than mass distribution, operators broke in via vulnerable JBoss servers and, later, brute-forced or stolen RDP credentials, then deployed the ransomware network-wide. It crippled the City of Atlanta, the Colorado Department of Transportation, and numerous hospitals. In November 2018 the U.S. DOJ indicted two Iranian nationals, attributing over USD 30 million in losses across 200+ victims.
Threat Actor
Two Iranian nationals (Faramarz Shahi Savandi, Mohammad Mehdi Shah Mansouri) indicted by the U.S. DOJ in 2018. Manual, targeted intrusions.
Technical Indicators
Encryption Extension
.encrypted / variant-specific (e.g. .weapologize, .keyxml)
Encryption Algorithm
AES (files) + RSA (key wrapping)
Ransom Note Name
'sorry'-themed HTML notes (e.g. HELP_DECRYPT_YOUR_FILES.html / 000-SORRY-FOR-FILES.html)
Targeted Industries
Government, Healthcare, Education, Transportation
First Seen
Late 2015 / January 2016
Last Seen
2018 (DOJ indictment)
Geographical Location
United States, Canada, United Kingdom
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 3 | T1190 | Exploit Public-Facing Application (JBoss) |
| T1133 | External Remote Services (RDP) | |
| T1078 | Valid Accounts | |
| Credential Access x 1 | T1110 | Brute Force |
| Execution x 1 | T1059.001 | PowerShell |
| Impact x 2 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery |