Ransomware Group intelligence
Samas
InactiveTrack Samas with 1 published victims in a single intelligence view.
Overview
Samas is tracked by Breach House as a ransomware group with 1 published victims.
United States is currently the most targeted country in this dataset.
No leak location metadata is currently available for this group.
Leak Status Distribution
- Leaked 0 0.0%
- Pending 1 100.0%
- Deleted 0 0.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (0)
No known leak locations available for this group.
Top Activity Sectors (1)
Typical Attacks (5)
▼How Samas typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via SamSam.
-
T1059.003 Windows Command Shell Execution
What they do: SamSam uses custom batch scripts to execute some of its components.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: SamSam has been seen using AES or DES to encrypt payloads and payload components.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1027.016 Junk Code Insertion Stealth
What they do: SamSam has used garbage code to pad some of its malware components.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: SamSam has been seen deleting its own files and payloads to make analysis of the attack more difficult.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1486 Data Encrypted for Impact Impact
What they do: SamSam encrypts victim files using RSA-2048 encryption and demands a ransom be paid in Bitcoin to decrypt those files.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Victims (1)
Search, filter and paginate the victim timeline for Samas. Showing 1–1 of 1.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Davidson County id240 View details | United States | Public Sector | — | pending | |
|
No additional victim description available. |
||||||