In this talk, we analyze the cyber-espionage attack that took place against the service centers of Samsung Italy in Spring 2018. To a certain extend, this is also similar to another one targeting Samsung's Assistance Centers in Russia. We see how the attack has evolved over the months, by analyzing the different campaigns and RATs used to access the victims' system. By reconstructing how the malware connected to its command&control server, we believe that the actors behind the attack were qualified; the spear-phishing emails sent to the victims were a starting point for a planned targeted attack with the goal of industrial espionage. Thanks to our threat intelligence activity, we have reconstructed the evolution of the attack and share our insights with the audience.