Netskope Threat Labs

SamSam

ATP Sandbox Adv. HeuristicsAVNetskope IPS

SamSam is a targeted ransomware operation known for methodical intrusions into healthcare, government, and education organizations. Its operators exploited vulnerable servers and weak credentials to enter networks quietly, moved laterally with stolen access, and encrypted on their own schedule rather than racing through the environment. The 2018 indictments of actors behind the family, including the Atlanta city government attack, made it a landmark case in ransomware enforcement.

First seen
February 2022
Last seen
October 2026
SamasSamsam

5 techniques across 3 tactics.

TA0002 Execution

TA0005 Stealth

TA0040 Impact

  • T1486Data Encrypted for Impact
Alert Name
Binary.Ransomware.Samas
ByteCode-MSIL.Ransomware.Samas
ByteCode-MSIL.Ransomware.SamSam
ByteCode-MSIL.Trojan.Samas
Gen:Variant.Ransom.Samas.1
Gen:Variant.Ransom.Samas.10
Gen:Variant.Ransom.Samas.13
Gen:Variant.Ransom.Samas.21
Gen:Variant.Ransom.Samas.8
Gen:Variant.Ransom.Samas.9