SamSam

S0370

Malware.View on attack.mitre.org

About this malware

SamSam is ransomware that appeared in early 2016. Unlike some ransomware, its variants have required operators to manually interact with the malware to execute some of its core components.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

SamSam has been seen using AES or DES to encrypt payloads and payload components.

T1027.016
Junk Code Insertion

SamSam has used garbage code to pad some of its malware components.

T1059.003
Windows Command Shell

SamSam uses custom batch scripts to execute some of its components.

T1070.004
File Deletion

SamSam has been seen deleting its own files and payloads to make analysis of the attack more difficult.

T1486
Data Encrypted for Impact

SamSam encrypts victim files using RSA-2048 encryption and demands a ransom be paid in Bitcoin to decrypt those files.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References4

  1. Sophos SamSam Apr 2018 Open source
    Palotay, D. and Mackenzie, P. (2018, April). SamSam Ransomware Chooses Its Targets Carefully. Retrieved April 15, 2019.
  2. Symantec SamSam Oct 2018 Open source
    Symantec Security Response Attack Investigation Team. (2018, October 30). SamSam: Targeted Ransomware Attacks Continue. Retrieved April 16, 2019.
  3. Talos SamSam Jan 2018 Open source
    Ventura, V. (2018, January 22). SamSam - The Evolution Continues Netting Over $325,000 in 4 Weeks. Retrieved April 16, 2019.
  4. US-CERT SamSam 2018 Open source
    US-CERT. (2018, December 3). Alert (AA18-337A): SamSam Ransomware. Retrieved March 15, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.