Monday, November 25, 2024
HomeRansomwareNew SamSam Ransomware Attack Around the World by Exploiting Organization Network Vulnerabilities

New SamSam Ransomware Attack Around the World by Exploiting Organization Network Vulnerabilities

Published on

SamSam Ransomware newly evolved with improved sophisticated capabilities and carefully selected the specific organizations such as hospitals, schools, and government sectors those who most likely to pay the ransom amount to get their data back.

Unlike other Ransomware, SamSam trying to exploiting the critical vulnerabilities in target organization network instead of using wide spreading Spam approach to compromise the target that used by other ransomware families.

Cybercriminals are distributing thousands of new copies that are highly obfusticated into the various specifically picked organization.

- Advertisement - SIEM as a Service

Previously Cisco Talos analysts noticed back in January, Attackers profited more than $300,000 with new SamSam Ransomware Campaign.

Attackers using a variety of vulnerability against the specific organization instead of using spam campaigns to gain access to the victim’s network also using brute force attack to exploit the weak passwords of the RDP protocol.

Once the attacker successfully gains the target network, it also seeking the additional network access using the stolen credentials and manually deploy the SamSam ransomware using specific tools such as PSEXEC and batch scripts.

SamSam Ransomware infection flow                                                                                         Credits: SOPHOS

How does SamSam Ransomware Works in Compromised Network

Initially, it used a patch file which has some responsibility such as executing the malware and deleting certain components to perform a specific operation during the execution of the  SamSam ransomware.

Later it executes with one argument that helps to decrypt the specific actual Payload and execute it on the infected victim’s host.

According to Sophos Analysts, a component called runner is responsible for decrypting and executing the payload. It is executed by the batch file with four parameters. The first one is the decryption password, which is followed by a string that is part of the .onion site address. Then the total ransom amount and the price per host values are given to the runner. It looks for a file with .stubbin extension. If it was found, the runner reads the content of the file, then deletes it. The read data will be decrypted in memory.
SamSam Ransomware Notes                                                                                                      Credits: SOPHOS

Also, it using two different component to increase the attack success ratio. if the first attack will be unsuccessful then attackers start the new attack by modifying the .exe file version.

After the many successful attacks in the various organization, attacker provided bitcoin address received 30.4 BTC till January and later they have moved into another account which has received around 23 Payment with a total income of 68.1 BTC.

Most of the Victims Paid full amount since the full price of the ransom amount will provide an access to the entire infected host in the network. some of the victims Paid per host.

IOC:

Bat:
6b21aec23a844e6a5af1879c41b9632a0e705bb7

713973f14ae8ff88a63a1491e82e48f362e3aed7

Runner:
3cbddf5f027b19e55366ecc0fd287f31379175a0 – z2.exe
Contains garbage code. Calls the decryption function from sdgasfse.dll.
a1ab74d2f06a542e77ea2c6d641aae4ed163a2da – mswinupdate.exe
Contains no garbage. Calls the decryption function from ClassLibrary1.dll

Dll:
138c3aae51e67db0c4134affae428fe91c0d1686 - sdgasfse.dll
4d7a60bd1fb3677a553f26d95430c107c8485129- ClassLibrary1.dll
Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Threat Actors Exploit Google Docs And Weebly Services For Malware Attacks

Phishing attackers used Google Docs to deliver malicious links, bypassing security measures and redirecting...

Python NodeStealer: Targeting Facebook Business Accounts to Harvest Login Credentials

The Python-based NodeStealer, a sophisticated info-stealer, has evolved to target new information and employ...

XSS Vulnerability in Bing.com Let Attackers Send Crafted Malicious Requests

A significant XSS vulnerability was recently uncovered in Microsoft’s Bing.com, potentially allowing attackers to...

Meta Removed 2 Million Account Linked to Malicious Activities

 Meta has announced the removal of over 2 million accounts connected to malicious activities,...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Helldown Ransomware Attacking VMware ESXi And Linux Servers

Helldown, a new ransomware group, actively exploits vulnerabilities to breach networks, as since August...

Phobos Ransomware Admin as Part of International Hacking Operation

The U.S. Department of Justice unsealed criminal charges today against Evgenii Ptitsyn, a 42-year-old Russian...

Black Basta Ransomware Leveraging Social Engineering For Malware Deployment

Black Basta, a prominent ransomware group, has rapidly gained notoriety since its emergence in...