Description Summary
Snatch ransomware first appeared in 2018 and operates as a ransomware-as-a-service. Its signature technique is forcing infected systems to reboot into Windows Safe Mode before encryption to bypass endpoint security tools that don't run in that mode. Snatch employs double extortion via its Tor leak site.
Threat Actor
Russian-speaking RaaS operators with affiliates worldwide.
Technical Indicators
Encryption Extension
.snatch
Encryption Algorithm
AES-256
Ransom Note Name
Readme_Restore_Files.txt
Targeted Industries
Defense Industrial Base, Food and Agriculture, IT, Healthcare
First Seen
2018
Last Seen
Active
Geographical Location
United States and globally
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 3 | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| T1078 | Valid Accounts | |
| Execution x 1 | T1059 | Command and Scripting Interpreter |
| Execution Persistence x 1 | T1053 | Scheduled Task/Job |
| Defense Evasion x 3 | T1562.001 | Disable or Modify Tools |
| T1070.004 | File Deletion | |
| T1562.009 | Safe Mode Boot | |
| Discovery x 2 | T1083 | File and Directory Discovery |
| T1082 | System Information Discovery | |
| Lateral Movement x 2 | T1021.001 | Remote Services: RDP |
| T1021.002 | SMB/Windows Admin Shares | |
| Exfiltration x 2 | T1041 | Exfiltration Over C2 Channel |
| T1567.002 | Exfiltration to Cloud Storage | |
| Impact x 3 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop |