SamSam Ransomware
ID: 819bf4f1-d68e-54f2-959c-ce796189130a
STIX ID: report--819bf4f1-d68e-54f2-959c-ce796189130a
Feed Name: CISA Cybersecurity Advisories
**Executive Summary:** This DHS/FBI alert describes the SamSam ransomware campaign that used JexBoss and, more commonly, compromised Remote Desktop Protocol (RDP) credentials (via brute force or darknet-bought credentials) to gain persistent access, escalate privileges, and deploy network-wide ransomware affecting primarily U.S. organizations and critical infrastructure; the report details actor tactics, indicators (ransom notes, Tor payment sites, credential theft), and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
