Skip to main content

SamSam ransomware has generated $5.9 million from victims since 2015

Image used with permission by copyright holder

Security firm Sophos reports that the SamSam ransomware has done more financial damage than previously believed, generating $5.9 million from victims since it originally appeared in December 2015. Sophos says hackers use SamSam in attacks about once per day, but the typical web surfer will likely never experience the devastation given SamSam’s target audience.

The sole task of ransomware is to hold a PC hostage by encrypting its data. For a fee, hackers will release that data. Ransomware is typically used in untargeted email spam campaigns where recipients click on an attachment or link that installs the ransomware on their PC. These campaigns typically don’t target specific people but flood the inboxes of hundreds of thousands of individuals.

According to Sophos, SamSam is different. It’s not used in a widespread spam campaign looking to hook potential victims. Instead, a single hacker or a team of individuals breaks into a network, scans the network, and then manually runs the ransomware. They are tailored attacks to maximize the damage and generate high-dollar ransoms.

“Perhaps most eye-catching though is new information about how it spreads,” the security firm reports. “Unlike WannaCry, which exploited a software vulnerability to copy itself to new machines, SamSam is actually deployed to computers on the victim’s network in the same way, and with the same tools, as legitimate software applications.”

Originally SamSam was believed to be used to solely attack healthcare, government, and educational organizations. But a deeper investigation reveals that companies in the private sector have actually taken the brunt of the attacks but are just unwilling to come forward to reveal their forced payments.

That said, businesses in the private sector account for 50 percent of the known attacks followed by healthcare (26 percent), government (13 percent), and education (11 percent) institutions.

A chart provided with the report shows that 74 percent of the victim organizations identified by Sophos reside within the United States. The United Kingdom trails with eight percent followed by Belgium, Canada, and Australia, while other countries such as Denmark, Estonia, the Netherlands, and India are one percent. There are other victims and countries Sophos has yet to identify.

The entire ransomware problem appears to stem from weak passwords. Hackers gain access to networks through the Remote Access Protocol that typically allows executives and workers to access the network remotely from a PC while at home or during a business trip. Hackers use software to guess these weak passwords and infiltrate the network.

But unlike WannaCry and NotPetya, hackers don’t unleash a worm that crawls through the network and infects every PC. Instead, they continually pound the network’s defenses until they get around the roadblocks and retrieve the access they want — or are booted from the network. From there, they move from PC to PC.

If the attack is successful, hackers wait to see if victims make payment through a website posted on the dark web. The ransoms have increased over time, Sophos claims, to around $50,000. Untargeted ransomware attacks such as spam campaigns typically only generate three-figure ransoms.

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Save $150 on a lifetime license for Microsoft Office for PC
microsoft office professional 2021 deal stack social april 2024 bundle

For one of the cheapest Office deals today, check out Stack Social which currently has a lifetime license for Microsoft Office Professional 2021 for Windows for just $70. The product normally costs $220 so you’re saving $150 off the regular price, all while gaining a lifetime license for some very useful software. If you’ve been considering getting Office and don’t want to deal with the ongoing nature of Office 365, this is a good opportunity to do so for less. Here’s what you need to know before you click the buy button.

Why you should buy Microsoft Office Professional 2021
If you’ve been reading up on whether to use Microsoft Word or Google Docs and you’ve settled on Word, snapping up Microsoft Office Professional 2021 is a great way to do so for less. Described as everything a pro needs, Microsoft Office Professional 2021 is pretty great.

Read more
Best Squarespace deals: Save on domains, web builder, and more
A laptop with Squarespace displayed on the screen.

Nowadays, everybody has a website, whether it's for personal stuff, to show off their online portfolio, or even to sell something. Of course, building a website isn't always easy, especially for those who aren't tech-savvy, but you'll be surprised at how easy it is to build a website with Squarespace, even for beginners. Luckily, there is currently a great sale going on at Squarespace to give you an extra nudge to grab yourself a subscription, with annual plans giving you up to 36% off, as well as a short-term 20% off sitewide with the code W4D20.

Besides just website building, there are a ton of perks of subscription, from hosting to email campaigns and even Squarespace Courses, which is pretty unique for a website-building website. So, if that sounds like something you'd like to be a part of, we've listed all the ways you can save on Squarespace subscriptions below.
Today’s best Squarespace deals

Read more
Microsoft Word free trial: Get a month of service for free
A person using MS Word.

It may not feel like it, but Microsoft Word is probably one of the most popular word processors out there, along with Google Docs, and pretty much everybody has likely used it at some point, regardless if you prefer Microsoft Office to Google Docs. Of course, if you want to get your hands on it these days, you're going to have to buy it as part of Microsoft Office, as opposed to getting it as a standalone product like you used to. While you do have to pay for the subscription, you can get Microsoft Word for a month using the free trial before it reverts to a paid subscription. Also, be sure to check out some of these useful Microsoft Words tricks and even how to run Microsoft Office on the Quest 3.
Is there a Microsoft Word free trial?

Microsoft Word is actually part of the company's wider Office app suite. Now known simply as Microsoft 365 (formerly Microsoft Office), Microsoft's enterprise software is available in a number of different packages that are now subscription-based; the company has retired the older bundles that were available for a one-time payment. That means if you want a Microsoft Word free trial, you'll need to sign up for the Microsoft 365 trial.

Read more