Saturday, January 18, 2025
HomeRansomwareNew SamSam Ransomware Attack Around the World by Exploiting Organization Network Vulnerabilities

New SamSam Ransomware Attack Around the World by Exploiting Organization Network Vulnerabilities

Published on

SIEM as a Service

Follow Us on Google News

SamSam Ransomware newly evolved with improved sophisticated capabilities and carefully selected the specific organizations such as hospitals, schools, and government sectors those who most likely to pay the ransom amount to get their data back.

Unlike other Ransomware, SamSam trying to exploiting the critical vulnerabilities in target organization network instead of using wide spreading Spam approach to compromise the target that used by other ransomware families.

Cybercriminals are distributing thousands of new copies that are highly obfusticated into the various specifically picked organization.

Previously Cisco Talos analysts noticed back in January, Attackers profited more than $300,000 with new SamSam Ransomware Campaign.

Attackers using a variety of vulnerability against the specific organization instead of using spam campaigns to gain access to the victim’s network also using brute force attack to exploit the weak passwords of the RDP protocol.

Once the attacker successfully gains the target network, it also seeking the additional network access using the stolen credentials and manually deploy the SamSam ransomware using specific tools such as PSEXEC and batch scripts.

SamSam Ransomware infection flow                                                                                         Credits: SOPHOS

How does SamSam Ransomware Works in Compromised Network

Initially, it used a patch file which has some responsibility such as executing the malware and deleting certain components to perform a specific operation during the execution of the  SamSam ransomware.

Later it executes with one argument that helps to decrypt the specific actual Payload and execute it on the infected victim’s host.

According to Sophos Analysts, a component called runner is responsible for decrypting and executing the payload. It is executed by the batch file with four parameters. The first one is the decryption password, which is followed by a string that is part of the .onion site address. Then the total ransom amount and the price per host values are given to the runner. It looks for a file with .stubbin extension. If it was found, the runner reads the content of the file, then deletes it. The read data will be decrypted in memory.
SamSam Ransomware Notes                                                                                                      Credits: SOPHOS

Also, it using two different component to increase the attack success ratio. if the first attack will be unsuccessful then attackers start the new attack by modifying the .exe file version.

After the many successful attacks in the various organization, attacker provided bitcoin address received 30.4 BTC till January and later they have moved into another account which has received around 23 Payment with a total income of 68.1 BTC.

Most of the Victims Paid full amount since the full price of the ransom amount will provide an access to the entire infected host in the network. some of the victims Paid per host.

IOC:

Bat:
6b21aec23a844e6a5af1879c41b9632a0e705bb7

713973f14ae8ff88a63a1491e82e48f362e3aed7

Runner:
3cbddf5f027b19e55366ecc0fd287f31379175a0 – z2.exe
Contains garbage code. Calls the decryption function from sdgasfse.dll.
a1ab74d2f06a542e77ea2c6d641aae4ed163a2da – mswinupdate.exe
Contains no garbage. Calls the decryption function from ClassLibrary1.dll

Dll:
138c3aae51e67db0c4134affae428fe91c0d1686 - sdgasfse.dll
4d7a60bd1fb3677a553f26d95430c107c8485129- ClassLibrary1.dll
Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Hackers Easily Bypass Active Directory Group Policy to Allow Vulnerable NTLMv1 Auth Protocol

Researchers have discovered a critical flaw in Active Directory’s NTLMv1 mitigation strategy, where misconfigured...

AWS Warns of Multiple Vulnerabilities in Amazon WorkSpaces, Amazon AppStream 2.0, & Amazon DCV

Amazon Web Services (AWS) has issued a critical security advisory highlighting vulnerabilities in specific...

FlowerStorm PaaS Platform Attacking Microsoft Users With Fake Login Pages

Rockstar2FA is a PaaS kit that mimics the legitimate credential-request behavior of cloud/SaaS platforms....

New Tool Unveiled to Scan Hacking Content on Telegram

A Russian software developer, aided by the National Technology Initiative, has introduced a groundbreaking...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

New NonEuclid RAT Evades Antivirus and Encrypts Critical Files

A NonEuclid sophisticated C# Remote Access Trojan (RAT) designed for the.NET Framework 4.8 has...

New Great Morpheus Hacker Group Claims Hacking Into Arrotex Pharmaceuticals And PUS GmbH

A Data Leak Site (DLS) belonging to a new extortion group named Morpheus, which...

1000’s Of SonicWall Devices Remain Vulnerable To CVE-2024-40766

A recent investigation revealed that the Akira and Fog ransomware groups are actively exploiting...