SamSam, also known as Samas, is a manually operated Windows ransomware family associated with some of the earliest prominent targeted ransomware intrusions against enterprise environments. First widely observed in 2016, it became notable for compromising internet-exposed servers rather than relying primarily on commodity spam or exploit-kit distribution. Early operations exploited vulnerable JBoss application servers and used web-shell and tunneling tooling to establish footholds, after which operators moved laterally and deployed ransomware across multiple systems. Later activity was also associated with compromise of exposed remote administration services such as RDP or VNC. Victims spanned multiple sectors, including healthcare, government, and industrial environments, and healthcare organizations were repeatedly highlighted among affected targets.
SamSam is characterized by hands-on-keyboard deployment and broad network impact. Operators typically obtained initial access to an exposed server, expanded access within the environment, and then encrypted multiple Windows hosts. The malware encrypts files using symmetric encryption with asymmetric protection of per-file keys, and variants were reported using Rijndael together with RSA-2048. Some variants enumerated drives using hardcoded drive letters, checked available disk space before writing encrypted output, and maintained exclusion lists to avoid encrypting selected paths. SamSam was also noted for affecting servers and network shares, amplifying operational disruption in enterprise networks.
The family evolved over time with stronger anti-analysis and anti-forensic measures. Later variants introduced string obfuscation and a loader that decrypted and executed an encrypted .NET payload, while deployment remained highly manual. SamSam has been observed deleting its own files and payloads to hinder analysis, and ATT&CK-aligned reporting also documents self-removal and artifact deletion behavior associated with the family. Unlike many ransomware families, some reported SamSam variants did not delete Volume Shadow Copies, which in limited cases could leave recovery opportunities.
Operationally, SamSam helped define the modern targeted ransomware model later adopted more broadly across the ecosystem: intrusion through exposed services or vulnerable internet-facing systems, internal expansion, and deliberate enterprise-wide encryption for maximum leverage. Public reporting has also linked SamSam activity to Iranian operators, and the group is frequently cited as an early example of ransomware used in large-company intrusions that foreshadowed later big-game hunting campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Once it finds a foothold — often by exploiting a weak password or one that doesn’t get changed often — it gets inside a system and starts to spread.
It is most likely distributed through exposed Remote Desktop Protocol (RDP)... The new ransomware is most likely spread through RDP... Like Nefilim, many of these ransomware attacks abuse exposed RDP ports.
attackers can use a wide variety of techniques to gain network access, including exploiting unpatched vulnerabilities... For example, the actors behind the SamSam attacks leveraged vulnerable servers exposed to the internet as their means of obtaining initial access
Once it finds a foothold — often by exploiting a weak password or one that doesn’t get changed often — it gets inside a system and starts to spread.
This time the adversaries have added some string obfuscation and improved the anti-analysis techniques used to make detection and analysis marginally more difficult.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
Previous versions of SamSam had an equivalent method for making payload access difficult by launching a thread that would wait 1 second before deleting itself from the hard disk.
The following analytic identifies potential Remote Desktop Protocol (RDP) brute force attacks by monitoring network traffic for RDP application activity.
The following analytic identifies potential Remote Desktop Protocol (RDP) brute force attacks by monitoring network traffic for RDP application activity... identifying source IPs that have made more than 10 successful connection attempts to the same RDP port on a host within a one-hour window.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
57 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tags: ... pay2key ... ransomware ... SamSam ...
Samas is described as ransomware, discussed in the context of multiple incident response engagements and analysis of the attack chain leading to ransomware deployment.
Named as an associated ransomware analytic story in the context of RDP brute-force activity.
Associated Analytic Story ... SamSam Ransomware
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.