The Department of Justice recently announced charges against two Iranian nationals for their involvement in the creation and development of the infamous SamSam ransomware.
The alleged hackers, Faramarz Shahi Savandi, 34 years old, and Mohammad Mehdi Shah, 27 years old, were charged with several cyber attacks.
The duo used SamSam ransomware to steal over $6 million since 2015 and caused over $30 million in damage to over 200 victims, including hospitals, municipalities, and public institutions.
According to the indictment, six charges weigh against Savandi and Mansouri, one of which concerns bank fraud.
Since the hackers live and operate in Iran, they have not yet been arrested by United States authorities, but the FBI has added them to the list of most wanted hackers.

Savandi and Mansouri created the first version of the SamSam Ransomware in December 2015 while the more advanced versions were released in June and October 2017.
Unlike most ransomwares, SamSam infected specific targets.
The hackers initially infected the Remote Desktop Protocol (RDP) on the target system either via brute force attacks or using stolen credentials, and then attempted to strategically deploy SamSam across the entire network by exploiting vulnerabilities in other systems.
Once spread across the network, SamSam encrypted system data and demanded a huge ransom payment (usually over $50,000) in Bitcoin in exchange for the decryption keys.
Informationally, since December 2015, SamSam has infected large organizations including the government of Atlanta, the Colorado Department of Transportation, many hospitals and educational institutions such as the state university of Mississippi Valley.
