Ransomware Group intelligence
Samas
InactiveTrack Samas with 1 published victims in a single intelligence view.
Overview
Samas is tracked by Breach House as a ransomware group with 1 published victims.
United States is currently the most targeted country in this dataset.
No leak location metadata is currently available for this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (0)
No known leak locations available for this group.
Top Activity Sectors (1)
Typical Attacks (5)
▼How Samas typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via SamSam.
-
T1059.003 Windows Command Shell Execution
What they do: SamSam uses custom batch scripts to execute some of its components.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: SamSam has been seen using AES or DES to encrypt payloads and payload components.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1027.016 Junk Code Insertion Stealth
What they do: SamSam has used garbage code to pad some of its malware components.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: SamSam has been seen deleting its own files and payloads to make analysis of the attack more difficult.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1486 Data Encrypted for Impact Impact
What they do: SamSam encrypts victim files using RSA-2048 encryption and demands a ransom be paid in Bitcoin to decrypt those files.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Victims (1)
Search, filter and paginate the victim timeline for Samas. Showing 1–1 of 1.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Davidson County id240 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||