SamSam
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The SamSam Gang, also known simply as SamSam, is a threat actor that has been publicly linked to ransomware operations targeting organizations within the United States of America. Open‑source reporting identifies the group by its aliases and notes that its known operational base, if any, is located in the United States. The actor’s observed victims include a municipal government—the City of Atlanta—and a private sector food importer also referred to as Atlanta in the sources, indicating a focus on U.S.-based entities across both public and private sectors. The primary objective demonstrated in these incidents is financial gain, as the attackers deployed ransomware that encrypted data and demanded a payment of fifty‑one thousand dollars to restore access. No public statements attribute espionage, political disruption, or ideological motives to the group’s activities.
In the reported attacks, the SamSam Gang employed the SAMSAM ransomware strain as the malicious payload that encrypted files on compromised systems. While the sources do not detail the exact initial access vectors used, the nature of the ransomware suggests the actors gained entry through methods typical of ransomware campaigns, such as exploiting vulnerable remote services or leveraging stolen credentials, though these specifics are not confirmed in the available material. The tooling style appears centered on deploying a single ransomware family rather than a diverse arsenal of malware or post‑exploitation frameworks. Attribution to a state sponsor or a larger criminal consortium has not been established in the public record; the group is described as an independent ransomware operator. The most notable operation attributed to SamSam is the March 2018 ransomware incident against the City of Atlanta, which disrupted online bill payments, court information access and other public‑facing services while leaving critical infrastructure such as public safety, water systems and airport functions unaffected. A second, contemporaneous incident involved a U.S. food importer also named Atlanta, where a similar ransomware demand was made, underscoring the actor’s pattern of targeting U.S. entities for financial extortion.
Incidents
Attributed incidents are available to members.
1 incident