Snatch Ransomware

Description Summary

Snatch ransomware first appeared in 2018 and operates as a ransomware-as-a-service. Its signature technique is forcing infected systems to reboot into Windows Safe Mode before encryption to bypass endpoint security tools that don't run in that mode. Snatch employs double extortion via its Tor leak site.

Threat Actor

Russian-speaking RaaS operators with affiliates worldwide.

Technical Indicators

Encryption Extension
.snatch
Encryption Algorithm
AES-256
Ransom Note Name
Readme_Restore_Files.txt
Targeted Industries
Defense Industrial Base, Food and Agriculture, IT, Healthcare
First Seen
2018
Last Seen
Active
Geographical Location
United States and globally

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 3 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 3 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
T1562.009 Safe Mode Boot
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 3 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop