Blog | G5 Cyber Security

SamSam: The Doctor Will See You, After He Pays The Ransom

Cisco Talos is observing a widespread campaign leveraging the Samas/Samsam/MSIL.B/C ransomware variant. Unlike most ransomware, SamSam is not launched via user focused attack vectors, such as phishing campaigns and exploit kits. This particular family seems to be distributed via compromising servers and using them as a foothold to move laterally through the network. A particular focus appears to have been placed on the healthcare industry. SamSam encrypts various file types (see Appendix A) and then encrypts that key with RSA-2048 bit encryption.”]

Source: https://blog.talosintelligence.com/2016/03/samsam-ransomware.html

Exit mobile version