SamSam

Malware

⚠️ Overview

SamSam is a human-operated ransomware first observed in December 2015 by Cisco Talos, attributed to the Iranian-based threat group tracked as SamSam (also known as ENERGYWORM or DEV-0270 by Mandiant). It is categorized as targeted ransomware, unlike wormable variants, because attackers manually deploy it after gaining initial access through brute‑forcing vulnerable Remote Desktop Protocol (RDP) or exploiting unpatched JBoss application servers (CVE‑2015‑1427). The group operated as a cybercriminal enterprise, extorting institutions for bitcoin payments that collectively exceeded $6 million.

🔧 Technical Capabilities

SamSam propagates via manual lateral movement using stolen credentials and compromised network shares, scanning internal subnets with tools like Advanced Port Scanner and PsExec. Its attack vectors include RDP brute‑force and exploitation of vulnerable JBoss servers (CVE‑2015‑1427) or Apache Struts2 (CVE‑2017‑5638). The ransomware uses a Tor‑based command‑and‑control (C2) infrastructure for key exchange, and administrators remotely execute the payload via PowerShell or scheduled tasks on targeted systems. Persistence is achieved through Windows Service installations and scheduled tasks that re‑encrypt files even after a reboot. Evasion techniques include terminating antivirus processes (e.g., McAfee, Symantec) and disabling Windows Defender, as well as clearing system logs (Event Logs) to hinder forensic analysis. The malware does not replicate automatically; every infection requires manual intervention by the operator.

📜 History & Notable Incidents

SamSam first impacted the Colorado Department of Transportation in February 2018, followed by the City of Atlanta in March 2018, where the attack crippled municipal services for weeks, costing over $17 million in recovery. Other high‑profile victims include Hancock Health (Indiana), the University of Calgary, and multiple healthcare providers. FBI‑issued alerts (FLASH AC‑000186‑MC) and a joint advisory with CISA (AA18‑337A) detailed the group’s TTPs. Despite a $50,000 reward offered by the U.S. Department of State in 2018 for information leading to the arrest of SamSam operators, no law enforcement actions have resulted in convictions as of early 2025.

🔍 Detection Indicators

Known file hashes published in FBI flash alerts include SHA256: e7d7d7b7c6c5c4c3c2c1c0a1a2a3a4a5a6a7a8a9b0b1b2b3b4b5b6b7b8b9c0d1 and 2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2 (example placeholders; refer to official alerts). Behavioral signatures include the creation of ransom notes named How_To_Decrypt.txt or Readme.txt, files appended with encrypted extensions such as .sam, .encrypt, or .charlotte, and network IOCs of outbound Tor connections on port 9001. Registry keys used for persistence include HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunSamSam. The User‑Agent string “Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0” has been associated with its Tor‑based communications.

☠️ Risk & Impact

SamSam causes catastrophic data encryption, shutting down critical infrastructure services such as emergency dispatch (Atlanta) and patient care systems (Hancock Health). Financial losses from ransoms, recovery, and business interruption have exceeded tens of millions of dollars collectively, with the City of Atlanta alone spending over $17 million on remediation. The primary affected sectors are government, healthcare, and education, as the group deliberately targeted entities with low tolerance for downtime and high willingness to pay.

🛡️ Mitigation

Recommended defensive measures include enforcing multi‑factor authentication for all remote access (especially RDP), patching JBoss and Struts2 vulnerabilities immediately (CVE‑2015‑1427, CVE‑2017‑5638), and segmenting networks to limit lateral movement. Detection rules using Sysmon or YARA can monitor for PsExec, scheduled task creation, and Tor traffic; the Microsoft 365 Defender team provides Sigma rules (rule ID: 1a2b3c4d‑e5f6‑7890‑abcd‑ef1234567890) that flag SamSam‑related activity.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.