Description
SamSam is a targeted ransomware operation known for methodical intrusions into healthcare, government, and education organizations. Its operators exploited vulnerable servers and weak credentials to enter networks quietly, moved laterally with stolen access, and encrypted on their own schedule rather than racing through the environment. The 2018 indictments of actors behind the family, including the Atlanta city government attack, made it a landmark case in ransomware enforcement.
Stats
- First seen
- February 2022
- Last seen
- October 2026
Also known as
SamasSamsam
MITRE ATT&CK techniques
5 techniques across 3 tactics.
Alert name variants
| Alert Name |
|---|
| Binary.Ransomware.Samas |
| ByteCode-MSIL.Ransomware.Samas |
| ByteCode-MSIL.Ransomware.SamSam |
| ByteCode-MSIL.Trojan.Samas |
| Gen:Variant.Ransom.Samas.1 |
| Gen:Variant.Ransom.Samas.10 |
| Gen:Variant.Ransom.Samas.13 |
| Gen:Variant.Ransom.Samas.21 |
| Gen:Variant.Ransom.Samas.8 |
| Gen:Variant.Ransom.Samas.9 |