Malware.View on attack.mitre.org
SamSam is ransomware that appeared in early 2016. Unlike some ransomware, its variants have required operators to manually interact with the malware to execute some of its core components.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
SamSam has been seen using AES or DES to encrypt payloads and payload components. |
| T1027.016 Junk Code Insertion |
SamSam has used garbage code to pad some of its malware components. |
| T1059.003 Windows Command Shell |
SamSam uses custom batch scripts to execute some of its components. |
| T1070.004 File Deletion |
SamSam has been seen deleting its own files and payloads to make analysis of the attack more difficult. |
| T1486 Data Encrypted for Impact |
SamSam encrypts victim files using RSA-2048 encryption and demands a ransom be paid in Bitcoin to decrypt those files. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.