logo

SamSam Ransomware

ID: 819bf4f1-d68e-54f2-959c-ce796189130a

STIX ID: report--819bf4f1-d68e-54f2-959c-ce796189130a

Feed Name: CISA Cybersecurity Advisories

Threat Score
78/100

Date Published: 2022-11-17

Date Updated: 2026-04-19

Author: CISA

...
...

**Executive Summary:** This DHS/FBI alert describes the SamSam ransomware campaign that used JexBoss and, more commonly, compromised Remote Desktop Protocol (RDP) credentials (via brute force or darknet-bought credentials) to gain persistent access, escalate privileges, and deploy network-wide ransomware affecting primarily U.S. organizations and critical infrastructure; the report details actor tactics, indicators (ransom notes, Tor payment sites, credential theft), and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.