The SamSam ransomware has reportedly collected over US$5.9mil (RM23.9mil) in payout so far, says security software firm Sophos.
First reported in late 2015, the ransomware is known for targeting medium to large public sector organisations in healthcare, education and government. However, the recent study states that this only makes up 50% of the total number of identified victims, and the rest, it claims, comprises "a private sector that has remained uncharacteristically quiet about the attacks".
The research SamSam: The (Almost) Six Million Dollar Ransomware, states that 74% of the known victims are based in the United States, while other regions known to have suffered attacks include Canada, Britain, and the Middle East. While there are no Malaysia-specific statistics in the study, reported cases closest to our region occurred in India (1%) and Australia (2%).
The largest amount of ransom paid by a victim stands at US$64,000 (RM260,000), says the report although it doesn't identify from who or where.Unlike other ransomwares where the spam campaign is sent to a large number of random people, those operating SamSam target their victims specifically.
The team – though the study also claims that it is possible for SamSam to be the work of one individual – break into a victim's network and monitor it closely before making a move. How the attacker identifies the organisations is unknown, says the report. They could be purchasing lists of vulnerable servers from other hackers on the dark web, or simply using publicly available search engines such as Shodan or Censys, it states.
SamSam attacks usually happen in the middle of the night or the early hours of the morning of the victim's local time zone when most users and admins would probably be unaware of the intrusion. The attackers often use software like "nlbrute" to correctly guess weak passwords and force their way into the victim's network via Remote Desktop Protocol (RDP).
A quick search on Shodan will generate thousands of IP addresses accessible over port 3389, the default RDP port, states the report.
Unlike WannaCry or NotPetya ransomwares, SamSam doesn't spread by itself. Instead, it has to be manually "distributed" by the human attacker, who by the time of the attack understand the environment and defences thanks to the initial surveillance.
Once in, the attackers will keep trying to increase their privileges to the Domain Admin level while they scan the network for valuable targets and deploy and execute the malware as a sysadmin using utilities such as PsExec or PaExec.
The ransomware not only encrypts document files, images, and other personal or work data, but also configuration and data files required to run applications (like Microsoft Office). Once the attack has been launched, the attacker waits to see if the victim contacts the attacker using the details provided in the ransom note.
The study shows that the victim roughly get seven days to pay the ransom, although, for an additional cost, this time can be extended. Working with cryptocurrency monitoring organisation Neutrino, the report shares that the ransom was demanded and paid in Bitcoins, and a total of 157 unique Bitcoin addresses have received ransom payments as well as 89 addresses which have been used on ransom notes and sample files but, to date, have not received payments.
To avoid becoming a victim, Sophos advises that the best defence against SamSam or any other form of malware is to adopt a layered, defence in depth approach to security. Staying on top of patching and also maintaining good password discipline will provide a formidable barrier to SamSam attacks.
This barrier can then be strengthened significantly with steps like restricting RDP access to staff connecting over a Virtual Private Network (VPN); using multi-factor authentication for VPN access and sensitive internal systems; complete regular vulnerability scans and penetration tests; and keeping backups offline and offsite.
Already a subscriber? Log in
Get 20% OFF The Star Digital Access
Cancel anytime. Ad-free. Unlimited access with perks.
