---
title: The True Cost of SamSam Ransomware | BitLyft Cybersecurity
description: Is your company protected from ransomware and malware? Do you have the latest technology to mitigate the latest threats?
image: https://www.bitlyft.com/hubfs/Imported_Blog_Media/Ransomware-header.jpg
---

[Skip to content](https://www.bitlyft.com/resources/the-true-cost-of-samsam-ransomware-in-the-hidden-threat#main-content)

[![BitLyft Cybersecurity](https://www.bitlyft.com/hubfs/BitLyft-header-logo.svg)](https://www.bitlyft.com/)

- Solutions
  
  Show submenu for Solutions 
  
    - [BitLyft True MDR](https://www.bitlyft.com/agentic-mdr)
      
      Show submenu for BitLyft True MDR 
      
          - [What is AMDR?](https://www.bitlyft.com/solutions/what-is-amdr)
          - [Security Automation](https://www.bitlyft.com/security-automation)
          - [Security Operation Center (SOC)](https://www.bitlyft.com/security-operations-center-soc)
          - [SIEM Management](https://www.bitlyft.com/security-information-and-event-management-siem)
          - [Central Threat Intelligence](https://www.bitlyft.com/central-threat-intelligence)
    - [BitLyft AIR®](https://www.bitlyft.com/air)
- Industries
  
  Show submenu for Industries 
  
    - [Banking](https://www.bitlyft.com/cybersecurity-for-banks)
    - [Public Utilities](https://www.bitlyft.com/managed-detection-and-response-for-public-utilities)
    - [DoD (CMMC)](https://www.bitlyft.com/cmmc-cybersecurity-compliance)
    - [NIST 800 - 171](https://www.bitlyft.com/nist-800-171)
    - [Healthcare](https://www.bitlyft.com/healthcare-cybersecurity)
    - [Higher Education](https://www.bitlyft.com/higher-education-cybersecurity)
    - [AI Data Center Security](https://www.bitlyft.com/ai-data-center-security)
    - [Cybersecurity for Aerospace](https://www.bitlyft.com/cybersecurity-for-aerospace)
    - [Energy and Utilities](https://www.bitlyft.com/energy-utilities-cybersecurity)
- [Pricing](https://www.bitlyft.com/agentic-managed-detection-response-pricing)
- [Partners](https://www.bitlyft.com/partners)
- Company
  
  Show submenu for Company 
  
    - [About Us](https://www.bitlyft.com/about-us)
    - [Careers](https://www.bitlyft.com/careers)
    - [Contact Us](https://www.bitlyft.com/contact-us)
- Resources
  
  Show submenu for Resources 
  
    - [Blog](https://www.bitlyft.com/resources)
    - [Case Studies](https://www.bitlyft.com/case-studies)
    - [Downloads](https://www.bitlyft.com/downloads)
    - [Glossary](https://www.bitlyft.com/glossary-of-terms)
- [Experienced a Breach?](https://bitlyft.com/emergency-incident-response)

Open main navigation

Close main navigation

- Solutions
  
  Show submenu for Solutions 
  
    - [BitLyft True MDR](https://www.bitlyft.com/agentic-mdr)
      
      Show submenu for BitLyft True MDR 
      
          - [What is AMDR?](https://www.bitlyft.com/solutions/what-is-amdr)
          - [Security Automation](https://www.bitlyft.com/security-automation)
          - [Security Operation Center (SOC)](https://www.bitlyft.com/security-operations-center-soc)
          - [SIEM Management](https://www.bitlyft.com/security-information-and-event-management-siem)
          - [Central Threat Intelligence](https://www.bitlyft.com/central-threat-intelligence)
    - [BitLyft AIR®](https://www.bitlyft.com/air)
- Industries
  
  Show submenu for Industries 
  
    - [Banking](https://www.bitlyft.com/cybersecurity-for-banks)
    - [Public Utilities](https://www.bitlyft.com/managed-detection-and-response-for-public-utilities)
    - [DoD (CMMC)](https://www.bitlyft.com/cmmc-cybersecurity-compliance)
    - [NIST 800 - 171](https://www.bitlyft.com/nist-800-171)
    - [Healthcare](https://www.bitlyft.com/healthcare-cybersecurity)
    - [Higher Education](https://www.bitlyft.com/higher-education-cybersecurity)
    - [AI Data Center Security](https://www.bitlyft.com/ai-data-center-security)
    - [Cybersecurity for Aerospace](https://www.bitlyft.com/cybersecurity-for-aerospace)
    - [Energy and Utilities](https://www.bitlyft.com/energy-utilities-cybersecurity)
- [Pricing](https://www.bitlyft.com/agentic-managed-detection-response-pricing)
- [Partners](https://www.bitlyft.com/partners)
- Company
  
  Show submenu for Company 
  
    - [About Us](https://www.bitlyft.com/about-us)
    - [Careers](https://www.bitlyft.com/careers)
    - [Contact Us](https://www.bitlyft.com/contact-us)
- Resources
  
  Show submenu for Resources 
  
    - [Blog](https://www.bitlyft.com/resources)
    - [Case Studies](https://www.bitlyft.com/case-studies)
    - [Downloads](https://www.bitlyft.com/downloads)
    - [Glossary](https://www.bitlyft.com/glossary-of-terms)
- [Experienced a Breach?](https://bitlyft.com/emergency-incident-response)
- [Request a Demo](https://www.bitlyft.com/request-a-demo)

[Request a Demo](https://www.bitlyft.com/request-a-demo)

[All posts](https://www.bitlyft.com/resources/all)

 April 13, 2023

# The True Cost of SamSam Ransomware

![circuit board with a red bug or virus](https://www.bitlyft.com/hubfs/Imported_Blog_Media/Ransomware-header.jpg)

![Picture of Jason Miller](https://www.bitlyft.com/hs-fs/hubfs/Headshots/JasonRound.png?width=50&name=JasonRound.png) By   Jason Miller  ·   3 minute read

Last year,[the city of Atlanta was attacked](https://www.wired.com/story/atlanta-ransomware-samsam-will-strike-again/) by a group of hackers who had infiltrated their system and effectively crippled large parts of it.

They were not alone. Just last year, the United States[indicted two Iranian nationals](https://www.welivesecurity.com/2018/11/29/us-indicts-samsam-ransomware-attacks/) who, themselves, had carried out over 200 attacks on organizations in the United States & Canada.

The attack? SamSam Ransomware.​

> The City of Atlanta is currently experiencing outages on various customer facing applications, including some that customers may use to pay bills or access court-related information. We will post any updates as we receive them. [pic.twitter.com/kc51rojhBl](https://t.co/kc51rojhBl)
> 
> — City of Atlanta, GA (@CityofAtlanta) [March 22, 2018](https://twitter.com/CityofAtlanta/status/976864741145694208?ref_src=twsrc%5Etfw)

 

<iframe class="hs-responsive-embed-iframe" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border: none;" xml="lang" src="https://www.youtube.com/embed/smzexA_bqD8" width="560" height="315" frameborder="0" allowfullscreen loading="lazy" data-service="youtube"></iframe>

 

## What is SamSam Ransomware?

The SamSam Ransomware attack is a type of [ransomware attack](https://www.bitlyft.com/resources/protecting-yourself-from-the-most-common-ransomware-attacks) released in 2016 that targeted JBoss servers. Unlike other ransomware attacks, which might use phishing, or drive-by-downloads to infect machines and find vulnerabilities, SamSam used a remote desktop brute-force attack to guess passwords.

Once one password was identified, the [malware](https://www.bitlyft.com/resources/malware-an-evolving-cyber-threat) makes its way through the rest of the network, using brute force and sophisticated algorithms to guess the passwords of other machines.

Once the malware has enough of a toe-hold in the network, it encrypts the information on the network, effectively preventing legitimate users from being able to access their machines.

Typically, the attackers then demand a ransom to ‘release’ the system, rendering it usable again.

Those two Iranian nationals indicted by the United States? According to the US Attorney,[made over $6 million and cost their targets approximately $30 million](https://www.justice.gov/opa/pr/two-iranian-men-indicted-deploying-ransomware-extort-hospitals-municipalities-and-public).

## Why Was the Attack Successful?

For the SamSam attack, the focus was largely on healthcare, local government organizations, and municipalities. The precise reason why those organizations were chosen is still unclear.

However, it’s not hard to imagine that organizations providing public services would be more likely to pay the ransom quickly, if for no other reason than the ransom is often priced as a ‘no-brainer.’ After all, who thinks about a [measly $55,000 when life-saving systems are potentially threatened](https://www.zdnet.com/article/us-hospital-pays-55000-to-ransomware-operators/)?

While many ransomware attacks are fairly indiscriminately spread (an unwitting user invites the malware), this one was specifically targeted towards the organizations assaulted.

### Warning Signs

In the case of SamSam, the malware does its best to ‘blend in’ until the network is significantly compromised. After a machine is compromised, the virus may sit silently for a day or two. Or maybe a few.

Then, when the timing is right, the attackers download hacking tools onto the computers in an organization. For example, they[loaded PSInfo and Mimikatz](https://www.symantec.com/blogs/threat-intelligence/samsam-targeted-ransomware-attacks) onto several machines to monitor information and steal passwords.

Then go silent again.

Until a few days later, when the encryption malware is loaded into the organization and executed across the organization. In the case of the Atlanta attack,[two versions of SamSam were loaded on](https://www.symantec.com/blogs/threat-intelligence/samsam-targeted-ransomware-attacks) in case one was detected by security software.

Unfortunately, this kind of ‘random’ activity can be difficult to track which is why it’s important to have a great SIEM being monitored by a [skilled security operations center team](https://www.bitlyft.com/security-operations-center) working together to identify and catch these aberrant events before they become incidents.

## Protecting Your People & Your System

SamSam, like many other kinds of attacks, is made easier when lax security controls are in place. For instance, permitting weak passwords (and not rotating them), not using two-factor authentication, and not investing in user education training are ways to inadvertently expose your network to vulnerabilities.

### Mitigations

Additionally, the US Department of Homeland Security suggests organizations:

- Audit your network for systems that use Remote Desktop Protocols (RDP) for remote communication and disabling if possible.
- Verify that all cloud-based virtual machine instances with public IPs have no open RDP ports, especially port 3389 unless there is a valid business reason to keep open RDP ports. Secure any system with an open RDP port behind a firewall and require users to use a virtual private network (VPN) to access that system.
- Enable [strong passwords](https://www.bitlyft.com/resources/cybersecurity-101-password-best-practices-to-use-in-2022) and account lockout policies to defend against brute force attacks.
- Use [two-factor authentication.](https://www.bitlyft.com/resources/cybersecurity-101-how-to-use-multi-factor-authentication)
- Regularly apply system and [software updates.](https://www.bitlyft.com/resources/cybersecurity-101-how-software-updates-can-keep-your-data-safe)
- Maintain a good back-up strategy.
- Enable logging and ensure that logging mechanisms capture RDP logins. Keep logs for a minimum of 90 days and review them regularly to detect intrusion attempts.
- When creating cloud-based virtual machines, adhere to the cloud provider’s best practices for remote access.
- Ensure that third parties that require RDP access follow internal policies on remote access.
- Minimize network exposure for all control system devices. Where possible, disable RDP on critical devices.
- Regulate and limit external-to-internal RDP connections. When external access to internal resources is required, use secure methods such as VPNs. Of course, VPNs are only as secure as the connected devices.
- Restrict users’ ability (permissions) to install and run unwanted software applications.
- Scan for and remove suspicious email attachments; ensure the scanned attachment is its “true file type” (i.e., the extension matches the file header).
- Disable file and printer sharing services. If these services are required, use strong passwords or Active Directory authentication.

Additionally, you want to make sure you’ve got good anti-virus protection on your machines, as well as backups of important data. While not a complete ‘security strategy,’ having backups can help reduce the cost of the attack.

Finally, you want to make sure you’re using a [SIEM](https://www.bitlyft.com/security-information-and-event-management) to monitor for abnormal events on your network, so that your security operations team can alert you to any potential threats – before they occur.

[![Hidden Threats and Cyber Attacks: Reveal and Respond to Some of the Hardest to Detect Cyber Attacks](https://no-cache.hubspot.com/cta/default/6764014/47fc4a54-0adf-40d4-99d4-82261d61bdd7.png)](https://cta-redirect.hubspot.com/cta/redirect/6764014/47fc4a54-0adf-40d4-99d4-82261d61bdd7)

Share: [facebook-f icon](http://www.facebook.com/share.php?u=https://www.bitlyft.com/resources/the-true-cost-of-samsam-ransomware-in-the-hidden-threat) [linkedin-in icon](http://www.linkedin.com/shareArticle?mini=true&url=https://www.bitlyft.com/resources/the-true-cost-of-samsam-ransomware-in-the-hidden-threat) [twitter icon](https://twitter.com/intent/tweet?url=https://www.bitlyft.com/resources/the-true-cost-of-samsam-ransomware-in-the-hidden-threat) [pinterest-p icon](http://pinterest.com/pin/create/link/?url=https://www.bitlyft.com/resources/the-true-cost-of-samsam-ransomware-in-the-hidden-threat) [envelope icon](mailto:?body=https://www.bitlyft.com/resources/the-true-cost-of-samsam-ransomware-in-the-hidden-threat)

[![Group 1000001766](https://www.bitlyft.com/hubfs/Group%201000001766.svg "Group 1000001766")](https://www.bitlyft.com)

[BitLyft AIR®](https://www.bitlyft.com/air)

[Agentic MDR](https://www.bitlyft.com/agentic-mdr)

[Partner](https://www.bitlyft.com/partners)

[Privacy Policy](https://www.bitlyft.com/privacy-policy)

[Careers](https://www.bitlyft.com/careers)

[Blog](https://www.bitlyft.com/resources)

[White Papers](https://www.bitlyft.com/downloads)

[Use Cases](https://www.bitlyft.com/case-studies)

[Miller Mindset Podcast](https://www.youtube.com/playlist?list=PLz7CtIA5QhhJgjIo3CUpdm7gm3Th6mrcm)

[About Us](https://www.bitlyft.com/about-us)

[Contact Us](https://www.bitlyft.com/contact-us)

[News](https://www.bitlyft.com/news)

[Get A Quote](https://www.bitlyft.com/get-a-quote)

[facebook-f icon](https://www.facebook.com/BitLyft) [linkedin-in icon](https://www.linkedin.com/company/bitlyft/) [twitter icon](https://twitter.com/bitlyft) [youtube icon](https://www.youtube.com/channel/UCGMnF3PMXFgTotrnPJfC87w)

Copyright © 2026, BitLyft Cybersecurity

[![BitLyft Cybersecurity](https://www.bitlyft.com/hubfs/BitLyft-header-logo.svg)](https://www.bitlyft.com)

Solutions

[FeaturedBitLyft AIR® Autonomous SOC — detection, response & remediation on autopilot, around the clock. Explore the platform](https://www.bitlyft.com/air)

Our Solutions

[BitLyft Agentic MDRFully managed detection & response](https://www.bitlyft.com/agentic-mdr) [Security AutomationAutomate the busywork of defense](https://www.bitlyft.com/security-automation) [Security Operations Center24/7 SOC coverage](https://www.bitlyft.com/security-operations-center-soc) [SIEM ManagementTuned, managed & monitored](https://www.bitlyft.com/security-information-and-event-management-siem) [Central Threat IntelligenceShared signal across customers](https://www.bitlyft.com/central-threat-intelligence) [BitLyft AIR®Automated incident response](https://www.bitlyft.com/air)

[What is AMDR?](https://www.bitlyft.com/solutions/what-is-amdr) [Plans & pricing](https://www.bitlyft.com/pricing) [Compare MDR vs. AIR NEW](https://www.bitlyft.com/true-mdr)

Industries

[Compliance-readyDoD & CMMC Meet CMMC and NIST 800-171 with security operations built for regulated sectors. See compliance coverage](https://www.bitlyft.com/cmmc)

Industries we protect

[Banking](https://www.bitlyft.com/banking) [FinTech](https://www.bitlyft.com/managed-detection-and-response-for-fintech) [Public Utilities](https://www.bitlyft.com/managed-detection-and-response-for-public-utilities) [DoD (CMMC)](https://www.bitlyft.com/cmmc) [NIST 800-171](https://www.bitlyft.com/nist-800-171) [Healthcare](https://www.bitlyft.com/managed-detection-and-response-for-healthcare) [Higher Education](https://www.bitlyft.com/higher-education) [AI Data Center Security](https://www.bitlyft.com/ai-data-center-security) [Cybersecurity for Aerospace](https://www.bitlyft.com/cybersecurity-for-aerospace) [Energy & Utilities](https://www.bitlyft.com/energy-and-utilities) [Manufacturing](https://www.bitlyft.com/agentic-mdr-for-manufacturing)

[Pricing](https://www.bitlyft.com/pricing) [Partners](https://www.bitlyft.com/partners)

Company

[Who we areAbout BitLyft On a mission to make elite cybersecurity accessible to every organization. Our story](https://www.bitlyft.com/about-us)

Company

[About Us](https://www.bitlyft.com/about-us) [Careers](https://www.bitlyft.com/careers) [Contact Us](https://www.bitlyft.com/contact-us)

Resources

[LearnBitLyft Blog Threat research, how-to guides and security insights from our SOC team. Read the blog](https://www.bitlyft.com/resources)

Resources

[Blog](https://www.bitlyft.com/resources) [Newsroom](https://www.bitlyft.com/news) [Case Studies](https://www.bitlyft.com/case-studies) [Downloads](https://www.bitlyft.com/downloads)

[Experienced a Breach?](https://bitlyft.com/emergency-incident-response) [Request a Demo](https://www.bitlyft.com/request-a-demo)

[Request a Demo](https://www.bitlyft.com/request-a-demo)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Jason Miller",
    "url" : "https://www.bitlyft.com/resources/author/jason-miller"
  },
  "dateModified" : "2023-04-13T17:59:52.037Z",
  "datePublished" : "2019-04-01T08:30:33.000Z",
  "headline" : "The True Cost of SamSam Ransomware | BitLyft Cybersecurity",
  "image" : [ "https://www.bitlyft.com/hubfs/Imported_Blog_Media/Ransomware-header.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.bitlyft.com/resources/the-true-cost-of-samsam-ransomware-in-the-hidden-threat",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.bitlyft.com/hubfs/BitLyft%20Logo%20(New)/BLLogo.svg"
    },
    "name" : "BitLyft"
  }
}
```

```json
{
  "@context" : "http://schema.org",
  "@type" : "Article",
  "author" : {
    "@type" : "Person",
    "name" : [ "Jason Miller" ]
  },
  "datePublished" : "2019-04-01T08:30:33+0000",
  "description" : "Is your company protected from ransomware and malware? Do you have the latest technology to mitigate the latest threats?",
  "headline" : "The True Cost of SamSam Ransomware",
  "image" : "https://f.hubspotusercontent10.net/hubfs/6764014/Imported_Blog_Media/Ransomware-header.jpg",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.bitlyft.com/hubfs/BitLyft%20Logo%20(New)/BLLogo.svg"
    },
    "name" : "BitLyft Cybersecurity"
  },
  "url" : "https://www.bitlyft.com/resources/the-true-cost-of-samsam-ransomware-in-the-hidden-threat"
}
```