{"id":82528,"date":"2018-04-24T09:54:28","date_gmt":"2018-04-24T16:54:28","guid":{"rendered":"https:\/\/www.backblaze.com\/blog\/?p=82528"},"modified":"2025-07-23T06:52:17","modified_gmt":"2025-07-23T13:52:17","slug":"ransomware-update-viruses-targeting-business-it-servers","status":"publish","type":"post","link":"https:\/\/www.backblaze.com\/blog\/ransomware-update-viruses-targeting-business-it-servers\/","title":{"rendered":"Ransomware Update: Viruses Targeting Business IT Servers"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-82529 size-full\" title=\"Ransomware News: SamSam Attacks Servers Directly \" src=\"https:\/\/www.backblaze.com\/blog\/wp-content\/uploads\/2018\/04\/samsam-ransomware.jpg\" alt=\"Ransomware warning message on computer\" width=\"1440\" height=\"820\" srcset=\"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/samsam-ransomware.jpg 1440w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/samsam-ransomware-300x171.jpg 300w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/samsam-ransomware-1024x583.jpg 1024w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/samsam-ransomware-768x437.jpg 768w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/samsam-ransomware-560x319.jpg 560w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/samsam-ransomware-220x124.jpg 220w\" sizes=\"auto, (max-width: 1440px) 100vw, 1440px\" \/><\/p>\n<p id=\"bzdropcap\">As ransomware attacks have grown in number in recent months, the tactics and attack vectors also have evolved. While the primary method of attack used to be to target individual computer users within organizations with phishing emails and infected attachments, we&#8217;re increasingly seeing attacks that target weaknesses in businesses&#8217; IT infrastructure.<\/p>\n<h2 class=\"b2\">How Ransomware Attacks Typically Work<\/h2>\n<p>In our <a href=\"\/blog\/tag\/ransomware\/\" rel=\"noopener noreferrer\" target=\"_blank\">previous posts on ransomware<\/a>, we described the common vehicles used by hackers to infect organizations with ransomware viruses. Most often, downloaders distribute trojan horses through malicious downloads and spam emails. The emails contain a variety of file attachments, which if opened, will download and run one of the many ransomware variants. Once a user\u2019s computer is infected with a malicious downloader, it will retrieve additional malware, which frequently includes crypto-ransomware. After the files have been encrypted, a ransom payment is demanded of the victim in order to decrypt the files.<\/p>\n<h3 class=\"b3\">What\u2019s Changed With the Latest Ransomware Attacks?<\/h3>\n<p>In 2016, a customized ransomware strain called <a href=\"https:\/\/www.symantec.com\/security-center\/writeup\/2016-030211-4046-99\" rel=\"noopener noreferrer\" target=\"_blank\">SamSam<\/a> began attacking the servers in primarily health care institutions. SamSam, unlike more conventional ransomware, is not delivered through downloads or phishing emails. Instead, the attackers behind SamSam use tools to identify unpatched servers running Red Hat\u2019s JBoss enterprise products. Once the attackers have successfully gained entry into one of these servers by exploiting vulnerabilities in JBoss, they use other freely available tools and scripts to collect credentials and gather information on networked computers. Then they deploy their ransomware to encrypt files on these systems before demanding a ransom. Gaining entry to an organization through its IT center rather than its endpoints makes this approach scalable and especially unsettling. <\/p>\n<p>SamSam&#8217;s methodology is to scour the Internet searching for accessible and vulnerable JBoss application servers, especially ones used by hospitals. It&#8217;s not unlike a burglar rattling doorknobs in a neighborhood to find unlocked homes. When SamSam finds an unlocked home (unpatched server), the software infiltrates the system. It is then free to spread across the company\u2019s network by stealing passwords. As it transverses the network and systems, it encrypts files, preventing access until the victims pay the hackers a ransom, typically between $10,000 and $15,000. The low ransom amount has encouraged some victimized organizations to pay the ransom rather than incur the downtime required to wipe and reinitialize their IT systems.<\/p>\n<p>The success of SamSam is due to its effectiveness rather than its sophistication. SamSam can enter and transverse a network without human intervention. Some organizations are learning too late that securing internet-facing services in their data center from attack is just as important as securing endpoints.<\/p>\n<p>The typical steps in a SamSam ransomware attack are:<\/p>\n<div align=\"center\">\n<table style=\"width: 100%; border-collapse: separate; border:0;\" cellpadding=\"3\">\n<tbody>\n<tr>\n<td style=\"vertical-align: middle; border: 4px solid #ccc; background-color: #f8f8f8; padding-bottom: 24px; text-align: center;\" width=\"30%\"><b><span style=\"font-size: 120%;\">1<\/span><br \/>\nAttackers gain access to vulnerable server<\/b><\/td>\n<td width=\"10px\" style=\"border: 0;\"><\/td>\n<td style=\"text-align: left; font-size: medium; border: 0;\">Attackers exploit vulnerable software or weak\/stolen credentials.<\/td>\n<\/tr>\n<tr>\n<td><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-79292\" src=\"https:\/\/www.backblaze.com\/blog\/wp-content\/uploads\/2017\/11\/down_solid_arrow_red.png\" alt=\"\" width=\"60\" height=\"30\" \/><\/td>\n<td style=\"border: 0;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"vertical-align: middle; border: 4px solid #ccc; background-color: #e8e8e8; padding-bottom: 24px; text-align: center;\"><b><span style=\"font-size: 120%;\">2<\/span><br \/>\nAttack spreads via remote access tools<\/b><\/td>\n<td style=\"border: 0;\"><\/td>\n<td style=\"text-align: left; font-size: medium; border: 0;\">Attackers harvest credentials, create SOCKS proxies to tunnel traffic, and abuse RDP to install SamSam on more computers in the network.<\/td>\n<\/tr>\n<tr>\n<td><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-79292\" src=\"https:\/\/www.backblaze.com\/blog\/wp-content\/uploads\/2017\/11\/down_solid_arrow_red.png\" alt=\"\" width=\"60\" height=\"30\" \/><\/td>\n<td style=\"border: 0;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"vertical-align: middle; border: 4px solid #ccc; background-color: #d8d8d8; padding-bottom: 24px; text-align: center;\"><b><span style=\"font-size: 120%;\">3<\/span><br \/>\nRansomware payload deployed<\/b><\/td>\n<td style=\"border: 0;\"><\/td>\n<td style=\"text-align: left; font-size: medium; border: 0;\">Attackers run batch scripts to execute ransomware on compromised machines.<\/td>\n<\/tr>\n<tr>\n<td><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-79292\" src=\"https:\/\/www.backblaze.com\/blog\/wp-content\/uploads\/2017\/11\/down_solid_arrow_red.png\" alt=\"\" width=\"60\" height=\"30\" \/><\/td>\n<td style=\"border: 0;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"vertical-align: middle; border: 4px solid #ccc; background-color: #c8c8c8; padding-bottom: 24px; text-align: center;\"><b><span style=\"font-size: 120%;\">4<\/span><br \/>\nRansomware demand delivered requiring payment to decrypt files<\/b><\/td>\n<td style=\"border: 0;\"><\/td>\n<td style=\"text-align: left; font-size: medium; border: 0;\">Demand amounts vary from victim to victim. Relatively low ransom amounts appear to be designed to encourage quick payment decisions.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>What all the organizations successfully exploited by SamSam have in common is that they were running unpatched servers that made them vulnerable to SamSam. Some organizations had their endpoints and servers backed up, while others did not. Some of the victims chose to pay the ransom &mdash; a strategy that in the past hasn&#8217;t guaranteed that the hackers will decrypt the hijacked files.<\/p>\n<h3 class=\"b3\">Timeline of SamSam History and Exploits<\/h3>\n<p>Since its appearance in 2016, SamSam has been in the news with many successful incursions into healthcare, business, and government institutions.<\/p>\n<div style=\"background-color: #f8f8f8; margin-top: 28px;\">\n<div class=\"timeline\">\n<div class=\"container left\">\n<div class=\"bz1_content\">\n<h5 style=\"text-align: center;\"><span style=\"color: #FF9E55;\">March 2016<\/span><br \/><span style=\"font-size: 80%;\">SamSam appears<\/span><\/h5>\n<p><strong>SamSam campaign targets vulnerable JBoss servers<\/strong><br \/>\nAttackers hone in on healthcare organizations specifically, as they\u2019re more likely to have unpatched JBoss machines.<\/p>\n<\/div>\n<\/div>\n<div class=\"container right\">\n<div class=\"bz1_content\">\n<h5 style=\"text-align: center;\"><span style=\"color: #FF9E55;\">April 2016<\/span><br \/><span style=\"font-size: 80%;\">SamSam finds new targets<\/span><\/h5>\n<p><strong>SamSam begins targeting schools and government.<\/strong><br \/>\nAfter initial success targeting healthcare, attackers branch out to other sectors.<\/p>\n<\/div>\n<\/div>\n<div class=\"container left\">\n<div class=\"bz1_content\">\n<h5 style=\"text-align: center;\"><span style=\"color: #FF9E55;\">April 2017<\/span><br \/><span style=\"font-size: 80%;\">New tactics include RDP<\/span><\/h5>\n<p><strong>Attackers shift to targeting organizations with exposed RDP connections, and maintain focus on healthcare.<\/strong><br \/>\nAn attack on Erie County Medical Center costs the hospital $10 million over three months of recovery.<br \/>\n<a href=\"\/blog\/wp-content\/uploads\/2018\/04\/erie_co_medical_center.jpg\" data-rel=\"lightbox-gallery-6fvXp0Zj\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.backblaze.com\/blog\/wp-content\/uploads\/2018\/04\/erie_co_medical_center.jpg\" alt=\"Erie County Medical Center attacked by SamSam ransomware virus\" width=\"1021\" height=\"630\" class=\"alignnone size-full wp-image-82807\" style=\"border: 1px solid #ccc;\" srcset=\"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/erie_co_medical_center.jpg 1021w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/erie_co_medical_center-300x185.jpg 300w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/erie_co_medical_center-768x474.jpg 768w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/erie_co_medical_center-560x346.jpg 560w\" sizes=\"auto, (max-width: 1021px) 100vw, 1021px\" \/><\/a>\n<\/div>\n<\/div>\n<div class=\"container right\">\n<div class=\"bz1_content\">\n<h5 style=\"text-align: center;\"><span style=\"color: #FF9E55;\">January 2018<\/span><br \/><span style=\"font-size: 80%;\">Municipalities attacked<\/span><\/h5>\n<p>\u2022 Attack on Municipality of Farmington, NM.<br \/>\n\u2022 Attack on Hancock Health.<br \/>\n<a href=\"\/blog\/wp-content\/uploads\/2018\/04\/hancock_regional_hospital_samsam2.jpg\" data-rel=\"lightbox-gallery-6fvXp0Zj\" data-rl_title=\"\" data-rl_caption=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-82690 size-full\" title=\"\" src=\"https:\/\/www.backblaze.com\/blog\/wp-content\/uploads\/2018\/04\/hancock_regional_hospital_samsam2.jpg\" alt=\"Hancock Regional Hospital notice following SamSam attack\" width=\"1200\" height=\"798\" srcset=\"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/hancock_regional_hospital_samsam2.jpg 1200w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/hancock_regional_hospital_samsam2-300x200.jpg 300w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/hancock_regional_hospital_samsam2-1024x681.jpg 1024w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/hancock_regional_hospital_samsam2-768x511.jpg 768w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/hancock_regional_hospital_samsam2-560x372.jpg 560w\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" \/><\/a><br \/>\n\u2022 Attack on Adams Memorial Hospital<br \/>\n\u2022 Attack on Allscripts (Electronic Health Records), which includes 180,000 physicians, 2,500 hospitals, and 7.2 million patients&#8217; health records.<\/p>\n<\/div>\n<\/div>\n<div class=\"container left\">\n<div class=\"bz1_content\">\n<h5 style=\"text-align: center;\"><span style=\"color: #FF9E55;\">February 2018<\/span><br \/><span style=\"font-size: 80%;\">Attack volume increases<\/span><\/h5>\n<p>\u2022 Attack on Davidson County, NC.<br \/>\n\u2022 Attack on Colorado Department of Transportation.<br \/>\n<a href=\"\/blog\/wp-content\/uploads\/2018\/04\/samsam-ransomware-infected-file-sensorstechforum-com-sorry-for-files-html-virus.png\" data-rel=\"lightbox-gallery-6fvXp0Zj\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.backblaze.com\/blog\/wp-content\/uploads\/2018\/04\/samsam-ransomware-infected-file-sensorstechforum-com-sorry-for-files-html-virus.png\" alt=\"SamSam virus notification\" width=\"1595\" height=\"967\" class=\"alignnone size-full wp-image-82804\" srcset=\"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/samsam-ransomware-infected-file-sensorstechforum-com-sorry-for-files-html-virus.png 1595w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/samsam-ransomware-infected-file-sensorstechforum-com-sorry-for-files-html-virus-300x182.png 300w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/samsam-ransomware-infected-file-sensorstechforum-com-sorry-for-files-html-virus-1024x621.png 1024w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/samsam-ransomware-infected-file-sensorstechforum-com-sorry-for-files-html-virus-768x466.png 768w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/samsam-ransomware-infected-file-sensorstechforum-com-sorry-for-files-html-virus-1536x931.png 1536w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/samsam-ransomware-infected-file-sensorstechforum-com-sorry-for-files-html-virus-560x340.png 560w\" sizes=\"auto, (max-width: 1595px) 100vw, 1595px\" \/><\/a>\n<\/div>\n<\/div>\n<div class=\"container right\">\n<div class=\"bz1_content\">\n<h5 style=\"text-align: center;\"><span style=\"color: #FF9E55;\">March 2018<\/span><br \/><span style=\"font-size: 76%;\">SamSam shuts down Atlanta<\/span><\/h5>\n<p>\u2022 Second attack on Colorado Department of Transportation.<br \/>\n\u2022 City of Atlanta suffers a devastating attack by SamSam.<br \/>\nThe attack has far-reaching impacts &mdash; crippling the court system, keeping residents from paying their water bills, limiting vital communications like sewer infrastructure requests, and pushing the Atlanta Police Department to file paper reports.<br \/>\n<a href=\"\/blog\/wp-content\/uploads\/2018\/04\/atlanta_samsam_outage_alert.jpg\" data-rel=\"lightbox-gallery-6fvXp0Zj\" data-rl_title=\"\" data-rl_caption=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-82688 size-full\" title=\"\" src=\"https:\/\/www.backblaze.com\/blog\/wp-content\/uploads\/2018\/04\/atlanta_samsam_outage_alert.jpg\" alt=\"Atlanta Ransomware outage alert\" width=\"1200\" height=\"1075\" srcset=\"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/atlanta_samsam_outage_alert.jpg 1200w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/atlanta_samsam_outage_alert-300x269.jpg 300w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/atlanta_samsam_outage_alert-1024x917.jpg 1024w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/atlanta_samsam_outage_alert-768x688.jpg 768w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/atlanta_samsam_outage_alert-560x502.jpg 560w\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" \/><\/a><br \/>\n\u2022 SamSam campaign nets $325,000 in 4 weeks.<br \/>\nInfections spike as attackers launch new campaigns. Healthcare and government organizations are once again the primary targets.<\/div>\n<\/div>\n<\/div>\n<\/div>\n<h2 class=\"b2\" style=\"margin-top: 28px;\">How to Defend Against SamSam and Other Ransomware Attacks<\/h2>\n<p>The best way to respond to a ransomware attack is to avoid having one in the first place. If you are attacked, making sure your valuable data is backed up and unreachable by ransomware infection will ensure that your downtime and data loss will be minimal or none if you ever suffer an attack.<\/p>\n<p>In our previous post, <a href=\"\/blog\/complete-guide-ransomware\/\" rel=\"noopener noreferrer\" target=\"_blank\">How to Recover From Ransomware<\/a>, we listed the ten ways to protect your organization from ransomware.<\/p>\n<ol>\n<li>Use anti-virus and anti-malware software or other security policies to block known payloads from launching.<\/li>\n<li>Make frequent, comprehensive backups of all important files and isolate them from local and open networks. Cybersecurity professionals view data backup and recovery (74% in a recent survey) by far as the most effective solution to respond to a successful ransomware attack.<\/li>\n<li>Keep offline backups of data stored in locations inaccessible from any potentially infected computer, such as disconnected external storage drives or the cloud, which prevents them from being accessed by the ransomware.<\/li>\n<li>Install the latest security updates issued by software vendors of your OS and applications. Remember to patch early and patch often to close known vulnerabilities in operating systems, server software, browsers, and web plugins.<\/li>\n<li>Consider deploying security software to protect endpoints, email servers, and network systems from infection.<\/li>\n<li>Exercise cyber hygiene, such as using caution when opening email attachments and links.<\/li>\n<li>Segment your networks to keep critical computers isolated and to prevent the spread of malware in case of attack. Turn off unneeded network shares.<\/li>\n<li>Turn off admin rights for users who don\u2019t require them. Give users the lowest system permissions they need to do their work.<\/li>\n<li>Restrict write permissions on file servers as much as possible.<\/li>\n<li>Educate yourself, your employees, and your family in best practices to keep malware out of your systems. Update everyone on the latest email phishing scams and human engineering aimed at turning victims into abettors.<\/li>\n<\/ol>\n<h3 class=\"b3\">Please Tell Us About Your Experiences with Ransomware<\/h3>\n<p>Have you endured a ransomware attack or have a strategy to avoid becoming a victim? Please tell us of your experiences in the comments.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As ransomware attacks have grown in number in recent months, the tactics and attack vectors also have evolved. While the primary method of attack used to be to target individual computer users within organizations, we&#8217;re increasingly seeing attacks that target weaknesses in businesses&#8217; IT infrastructure.<\/p>\n","protected":false},"author":133,"featured_media":82529,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","footnotes":""},"categories":[475],"tags":[471,351],"class_list":["post-82528","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ransomware","tag-businessbackup","tag-ransomware","entry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Ransomware News: SamSam Moves Beyond Email to Attack Servers<\/title>\n<meta name=\"description\" content=\"While the primary method of attack used to be to target individual computer users within organizations with phishing emails and infected attachments, we&#039;re increasingly seeing attacks that target weaknesses in businesses&#039; IT infrastructure.\" \/>\n<meta name=\"robots\" content=\"noindex, follow\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Ransomware News: SamSam Moves Beyond Email to Attack Servers\" \/>\n<meta property=\"og:description\" content=\"While the primary method of attack used to be to target individual computer users within organizations with phishing emails and infected attachments, we&#039;re increasingly seeing attacks that target weaknesses in businesses&#039; IT infrastructure.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.backblaze.com\/blog\/ransomware-update-viruses-targeting-business-it-servers\/\" \/>\n<meta property=\"og:site_name\" content=\"Backblaze Blog | Cloud Storage &amp; Cloud Backup\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/backblaze\" \/>\n<meta property=\"article:published_time\" content=\"2018-04-24T16:54:28+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-07-23T13:52:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/samsam-ransomware.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1440\" \/>\n\t<meta property=\"og:image:height\" content=\"820\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Roderick Bauer\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@rodbauer\" \/>\n<meta name=\"twitter:site\" content=\"@backblaze\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Roderick Bauer\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Ransomware News: SamSam Moves Beyond Email to Attack Servers","description":"While the primary method of attack used to be to target individual computer users within organizations with phishing emails and infected attachments, we're increasingly seeing attacks that target weaknesses in businesses' IT infrastructure.","robots":{"index":"noindex","follow":"follow"},"og_locale":"en_US","og_type":"article","og_title":"Ransomware News: SamSam Moves Beyond Email to Attack Servers","og_description":"While the primary method of attack used to be to target individual computer users within organizations with phishing emails and infected attachments, we're increasingly seeing attacks that target weaknesses in businesses' IT infrastructure.","og_url":"https:\/\/www.backblaze.com\/blog\/ransomware-update-viruses-targeting-business-it-servers\/","og_site_name":"Backblaze Blog | Cloud Storage &amp; Cloud Backup","article_publisher":"https:\/\/www.facebook.com\/backblaze","article_published_time":"2018-04-24T16:54:28+00:00","article_modified_time":"2025-07-23T13:52:17+00:00","og_image":[{"width":1440,"height":820,"url":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/samsam-ransomware.jpg","type":"image\/jpeg"}],"author":"Roderick Bauer","twitter_card":"summary_large_image","twitter_creator":"@rodbauer","twitter_site":"@backblaze","twitter_misc":{"Written by":"Roderick Bauer","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.backblaze.com\/blog\/ransomware-update-viruses-targeting-business-it-servers\/#article","isPartOf":{"@id":"https:\/\/www.backblaze.com\/blog\/ransomware-update-viruses-targeting-business-it-servers\/"},"author":{"name":"Roderick Bauer","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#\/schema\/person\/ab76c78d649d9b862757dfa400d3cb8d"},"headline":"Ransomware Update: Viruses Targeting Business IT Servers","datePublished":"2018-04-24T16:54:28+00:00","dateModified":"2025-07-23T13:52:17+00:00","mainEntityOfPage":{"@id":"https:\/\/www.backblaze.com\/blog\/ransomware-update-viruses-targeting-business-it-servers\/"},"wordCount":1183,"commentCount":0,"publisher":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.backblaze.com\/blog\/ransomware-update-viruses-targeting-business-it-servers\/#primaryimage"},"thumbnailUrl":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/samsam-ransomware.jpg","keywords":["BusinessBackup","Ransomware"],"articleSection":["Ransomware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.backblaze.com\/blog\/ransomware-update-viruses-targeting-business-it-servers\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.backblaze.com\/blog\/ransomware-update-viruses-targeting-business-it-servers\/","url":"https:\/\/www.backblaze.com\/blog\/ransomware-update-viruses-targeting-business-it-servers\/","name":"Ransomware News: SamSam Moves Beyond Email to Attack Servers","isPartOf":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.backblaze.com\/blog\/ransomware-update-viruses-targeting-business-it-servers\/#primaryimage"},"image":{"@id":"https:\/\/www.backblaze.com\/blog\/ransomware-update-viruses-targeting-business-it-servers\/#primaryimage"},"thumbnailUrl":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/samsam-ransomware.jpg","datePublished":"2018-04-24T16:54:28+00:00","dateModified":"2025-07-23T13:52:17+00:00","description":"While the primary method of attack used to be to target individual computer users within organizations with phishing emails and infected attachments, we're increasingly seeing attacks that target weaknesses in businesses' IT infrastructure.","breadcrumb":{"@id":"https:\/\/www.backblaze.com\/blog\/ransomware-update-viruses-targeting-business-it-servers\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.backblaze.com\/blog\/ransomware-update-viruses-targeting-business-it-servers\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.backblaze.com\/blog\/ransomware-update-viruses-targeting-business-it-servers\/#primaryimage","url":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/samsam-ransomware.jpg","contentUrl":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/samsam-ransomware.jpg","width":1440,"height":820},{"@type":"BreadcrumbList","@id":"https:\/\/www.backblaze.com\/blog\/ransomware-update-viruses-targeting-business-it-servers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Ransomware Update: Viruses Targeting Business IT Servers"}]},{"@type":"WebSite","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#website","url":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/","name":"Backblaze Cloud Solutions Blog","description":"Cloud Storage &amp; Cloud Backup","publisher":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#organization","name":"Backblaze","url":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/www.backblaze.com\/blog\/wp-content\/uploads\/2017\/12\/backblaze_icon_transparent.png?fit=512%2C512&ssl=1","contentUrl":"https:\/\/i0.wp.com\/www.backblaze.com\/blog\/wp-content\/uploads\/2017\/12\/backblaze_icon_transparent.png?fit=512%2C512&ssl=1","width":512,"height":512,"caption":"Backblaze"},"image":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/backblaze","https:\/\/x.com\/backblaze","https:\/\/www.youtube.com\/user\/Backblaze","https:\/\/en.wikipedia.org\/wiki\/Backblaze"]},{"@type":"Person","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#\/schema\/person\/ab76c78d649d9b862757dfa400d3cb8d","name":"Roderick Bauer","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/d0f9ff246abfe724e25d1c41983affb76e691cd3577d8b4d0d7607ee3ab6cbe2?s=96&d=blank&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d0f9ff246abfe724e25d1c41983affb76e691cd3577d8b4d0d7607ee3ab6cbe2?s=96&d=blank&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d0f9ff246abfe724e25d1c41983affb76e691cd3577d8b4d0d7607ee3ab6cbe2?s=96&d=blank&r=g","caption":"Roderick Bauer"},"description":"Roderick has held marketing, engineering, and product management positions with Adobe, Microsoft, Autodesk, and several startups. He's consulted to Apple, Microsoft, Hewlett-Packard, Stanford University, Dell, the Pentagon, and the White House. He was a Ford-Mozilla Fellow in Media and Democracy with Common Cause in Washington, D.C., where he advocated for a free, open, and accessible internet for all, reducing media consolidation, and transparency in politics and the media.","sameAs":["https:\/\/x.com\/rodbauer"],"url":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/author\/roderick\/"}]}},"jetpack_featured_media_url":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2018\/04\/samsam-ransomware.jpg","_links":{"self":[{"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/posts\/82528","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/users\/133"}],"replies":[{"embeddable":true,"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/comments?post=82528"}],"version-history":[{"count":0,"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/posts\/82528\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/media\/82529"}],"wp:attachment":[{"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/media?parent=82528"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/categories?post=82528"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/tags?post=82528"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}