Saturday, December 28, 2024
HomeRansomwareNew SamSam Ransomware Attack Around the World by Exploiting Organization Network Vulnerabilities

New SamSam Ransomware Attack Around the World by Exploiting Organization Network Vulnerabilities

Published on

SIEM as a Service

SamSam Ransomware newly evolved with improved sophisticated capabilities and carefully selected the specific organizations such as hospitals, schools, and government sectors those who most likely to pay the ransom amount to get their data back.

Unlike other Ransomware, SamSam trying to exploiting the critical vulnerabilities in target organization network instead of using wide spreading Spam approach to compromise the target that used by other ransomware families.

Cybercriminals are distributing thousands of new copies that are highly obfusticated into the various specifically picked organization.

- Advertisement - SIEM as a Service

Previously Cisco Talos analysts noticed back in January, Attackers profited more than $300,000 with new SamSam Ransomware Campaign.

Attackers using a variety of vulnerability against the specific organization instead of using spam campaigns to gain access to the victim’s network also using brute force attack to exploit the weak passwords of the RDP protocol.

Once the attacker successfully gains the target network, it also seeking the additional network access using the stolen credentials and manually deploy the SamSam ransomware using specific tools such as PSEXEC and batch scripts.

SamSam Ransomware infection flow                                                                                         Credits: SOPHOS

How does SamSam Ransomware Works in Compromised Network

Initially, it used a patch file which has some responsibility such as executing the malware and deleting certain components to perform a specific operation during the execution of the  SamSam ransomware.

Later it executes with one argument that helps to decrypt the specific actual Payload and execute it on the infected victim’s host.

According to Sophos Analysts, a component called runner is responsible for decrypting and executing the payload. It is executed by the batch file with four parameters. The first one is the decryption password, which is followed by a string that is part of the .onion site address. Then the total ransom amount and the price per host values are given to the runner. It looks for a file with .stubbin extension. If it was found, the runner reads the content of the file, then deletes it. The read data will be decrypted in memory.
SamSam Ransomware Notes                                                                                                      Credits: SOPHOS

Also, it using two different component to increase the attack success ratio. if the first attack will be unsuccessful then attackers start the new attack by modifying the .exe file version.

After the many successful attacks in the various organization, attacker provided bitcoin address received 30.4 BTC till January and later they have moved into another account which has received around 23 Payment with a total income of 68.1 BTC.

Most of the Victims Paid full amount since the full price of the ransom amount will provide an access to the entire infected host in the network. some of the victims Paid per host.

IOC:

Bat:
6b21aec23a844e6a5af1879c41b9632a0e705bb7

713973f14ae8ff88a63a1491e82e48f362e3aed7

Runner:
3cbddf5f027b19e55366ecc0fd287f31379175a0 – z2.exe
Contains garbage code. Calls the decryption function from sdgasfse.dll.
a1ab74d2f06a542e77ea2c6d641aae4ed163a2da – mswinupdate.exe
Contains no garbage. Calls the decryption function from ClassLibrary1.dll

Dll:
138c3aae51e67db0c4134affae428fe91c0d1686 - sdgasfse.dll
4d7a60bd1fb3677a553f26d95430c107c8485129- ClassLibrary1.dll
Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Lumma Stealer Attacking Users To Steal Login Credentials From Browsers

Researchers observed Lumma Stealer activity across multiple online samples, including PowerShell scripts and a...

New ‘OtterCookie’ Malware Attacking Software Developers Via Fake Job Offers

Palo Alto Networks reported the Contagious Interview campaign in November 2023, a financially motivated...

NjRat 2.3D Pro Edition Shared on GitHub: A Growing Cybersecurity Concern

The recent discovery of the NjRat 2.3D Professional Edition on GitHub has raised alarms...

Palo Alto Networks Vulnerability Puts Firewalls at Risk of DoS Attacks

A critical vulnerability, CVE-2024-3393, has been identified in the DNS Security feature of Palo...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

17M Patient Records Stolen in Ransomware Attack on Three California Hospitals

A staggering 17 million patient records, containing sensitive personal and medical information, have been...

NotLockBit – Previously Unknown Ransomware Attack Windows & macOS

A new and advanced ransomware family, dubbed NotLockBit, has emerged as a significant threat...

US Charged Chinese Hackers for Exploiting Thousands of Firewall

The US Treasury Department's Office of Foreign Assets Control (OFAC) has sanctioned Sichuan Silence...