Ransomware Group intelligence
Samsam
InactiveTrack Samsam with 12 published victims in a single intelligence view.
Overview
Samsam is tracked by Breach House as a ransomware group with 12 published victims.
United States is currently the most targeted country in this dataset.
No leak location metadata is currently available for this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (0)
No known leak locations available for this group.
Top Activity Sectors (7)
Typical Attacks (5)
▼How Samsam typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via SamSam.
-
T1059.003 Windows Command Shell Execution
What they do: SamSam uses custom batch scripts to execute some of its components.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: SamSam has been seen using AES or DES to encrypt payloads and payload components.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1027.016 Junk Code Insertion Stealth
What they do: SamSam has used garbage code to pad some of its malware components.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: SamSam has been seen deleting its own files and payloads to make analysis of the attack more difficult.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1486 Data Encrypted for Impact Impact
What they do: SamSam encrypts victim files using RSA-2048 encryption and demands a ransom be paid in Bitcoin to decrypt those files.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Crypto Wallets (48)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
1NHgHGYm2f5Acu4XC17EKoMLDAHC5143G8 |
bitcoin | $34,502 | 1 |
1F2K3zxpjTWDL7aBt497cVqUJUG3G85rkE |
bitcoin | $30,827 | 2 |
1GWQv1LmYCVk6cKikarV2hC6RJBULZ26am |
bitcoin | $29,500 | 2 |
193D1yarHanBhTETzvEAZ7qxnTzgD2Pqor |
bitcoin | $28,375 | 2 |
1DxYrRu3fkqj2iLjL4a55e4n3bWAF9mBNU |
bitcoin | $27,289 | 1 |
16VckpWyEzDCC7zD2uGTwjYAVXE3EZctBY |
bitcoin | $27,236 | 3 |
13R8c99CsCMr7iz73NYYEWjsEqYp9fLtdt |
bitcoin | $26,880 | 3 |
1KzVLJcZky4wDjhCKjJiS8HnxurGusjCnG |
bitcoin | $25,868 | 2 |
1A1rUVvjVLWvUeBNHbxyur9ebs3p8UTKjL |
bitcoin | $25,587 | 3 |
1HCvm76tKdTEHfrsVBGm3hiPRHCSHTVLf8 |
bitcoin | $24,207 | 1 |
1DcCFq3n5ptvxZpCD485sHX2EJmpCBK3Ds |
bitcoin | $23,201 | 2 |
1KwgwwWdoL9VFcg9VuCDGBiVZ2LNzGnrov |
bitcoin | $22,241 | 5 |
+36 more wallets not shown (the 12 largest by amount received are listed).
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Victims (12)
Search, filter and paginate the victim timeline for Samsam. Showing 1–12 of 12.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Port of San Diego (Harbor and PD) id253 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | LabCorp id248 View details | United States | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Atlanta (and Atlanta PD) id244 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Mississippi Valley State University id243 View details | United States | Education | — | |
|
No additional victim description available. |
|||||
| Ransomware | Colorado Department of Transportation (CDOT) id241 View details | United States | Transportation / Travel / Logistics | — | |
|
No additional victim description available. |
|||||
| Ransomware | Allscripts Healthcare Solutions, Inc. id239 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Hancock Health id238 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | City of Farmington id237 View details | United States | Agriculture / Food | — | |
|
No additional victim description available. |
|||||
| Ransomware | Montgomery County (Alabama) id236 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | City of Newark id200 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | University of Calgary id192 View details | Canada | Education | — | |
|
No additional victim description available. |
|||||
| Ransomware | MedStar Health Baltimore id187 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||