Cybersecurity Notification: SamSam Ransomware Campaign

Apr 06, 2018 | Katie Dwyer

A recent wave of cyber “ransomware” attacks known as SamSam has impacted healthcare and governmental organizations throughout the country. The following unclassified summary of SamSam was adapted from a report developed by the Healthcare Cybersecurity and Communications Integration Center (HCCIC), in coordination with the HHS Computer Security Incident Response Center (CSIRC).

In 2018, there have been at least eight separate cyber-attacks on healthcare and government organizations utilizing a form of ransomware known as SamSam. This has included two Indiana-based hospitals, an electronic health record provider, and various systems and public services in Colorado, North Carolina, New Mexico, and Atlanta, Georgia.

Authorities believe these attacks are not necessarily targeted and appear to be more opportunistic in nature. As in previous campaigns, attackers are believed to gain initial access to the target systems through open vulnerabilities, before gaining access to additional computers once inside the network and deploying the SamSam malware.

In order to prevent attackers from gaining access to servers via RDP, as is the case with many ransomware events, the following mitigations strategies are recommended:

  • restrict access behind firewalls and by using a RDP Gateway, VPNs
  • use strong/unique username and passwords with two-factor authentication (2FA)
  • limit users who can log in using remote desktop
  • implement an account lockout policy to help thwart brute force attacks (set a maximum number of attempts before locking out the account)

The following practices should be considered to help ensure business and healthcare continuity in the face of potential disruptions from ransomware or other factors:

  • Back up data regularly, and verify the integrity of those backups and test the restoration process to ensure it is working
  • Conduct an annual penetration test and vulnerability assessment
  • Secure your backups – ensure backups are not connected permanently to the computers and networks they are backing up. Examples include securing backups in the cloud or physically storing backup data offline. Some instances of ransomware have the capability to lock cloud-based backups when systems continuously backup in real time, also known as persistent synchronization. Backups are critical in ransomware recovery and response; if infected, a backup may be the best way to recover critical data.

For more information, view the full report. For questions relating to the content in the report e-mail the HCCIC at [email protected].

This posting is being shared on behalf of the Healthcare and Public Health sector.


About Katie Dwyer

More posts by Katie Dwyer

Related Posts

Extreme Heat web
  • Tools & Resources

Nation’s First Health-Based Heat Forecast and Clinical...

New resources offer proactive steps people can take to protect themselves from...

Apr 22, 2024

Nation’s First Health-Based Heat Forecast and Clinical...

Philly MRC web main
  • Medical Reserve Corps

Fostering Volunteer Retention and Engagement through...

See how the Philadelphia Medical Reserve Corps builds and fosters connections...

Apr 18, 2024 | Beth Hess

Fostering Volunteer Retention and Engagement through...

Opportunity
  • Call for Comments

Feedback Requested: Incident Response Recommendations...

Share feedback on Incident Response Recommendations and Considerations for...

Apr 10, 2024 | Shannon Duffy

Feedback Requested: Incident Response Recommendations...

2024 Ready Or Not
  • Extreme Weather Research & Reports

Ready or Not 2024: Protecting the Public’s Health from...

New report measures states’ preparedness to respond to a spectrum of health...

Apr 10, 2024 | Beth Hess

Ready or Not 2024: Protecting the Public’s Health from...

Crowd 600px
  • Tools & Resources Training

Recap: 2024 Preparedness Summit

See highlights from the 2024 Preparedness Summit.

Apr 08, 2024 | Beth Hess

Recap: 2024 Preparedness Summit

PPHR 600px
  • Opportunity Project Public Health Ready (PPHR)

Join the PPHR National Review Team

Applications open through June 28.

Apr 05, 2024 | Beth Hess

Join the PPHR National Review Team

Workgroup graphic web
  • Opportunity

Join a Preparedness Workgroup

Workgroup applications open through April 30.

Apr 05, 2024 | Beth Hess

Join a Preparedness Workgroup

Thank You web
  • Medical Reserve Corps

Resources for National Volunteer Month

See resources for recognizing volunteers during National Volunteer Month.

Apr 05, 2024 | Beth Hess

Resources for National Volunteer Month

Reflector web
  • Medical Reserve Corps

Medical Reserve Corps Units Focus on Pedestrian Safety

See how MRC units in Vermont are promoting pedestrian safety.

Apr 05, 2024

Medical Reserve Corps Units Focus on Pedestrian Safety

Back to Top