Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors snatch

Description

Snatch is a ransomware which infects victims by rebooting the PC into Safe Mode. Most of the existing security protections do not run in Safe Mode so that it the malware can act without expected countermeasures and it can encrypt as many files as it finds. It uses common packers such as UPX to hide its payload. Known victims: 142 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 2 weeks ago

Executive Summary

Snatch is a medium-sophistication criminal threat actor primarily involved in ransomware activities for financial gain. The group targets various sectors globally, leveraging safe-mode infections and encryption techniques to disrupt organizations. With 142 known victims and continuous operations since November 2021, Snatch poses a significant risk through its strategic approach to evade detection and maximize impact.

Goals & Targeting

Snatch's objectives are centered around financial gain through ransomware activities. They target organizations across multiple sectors globally, exploiting vulnerabilities that provide high potential for payout without over-specific exposure risks. The choice of sectors is strategic, focusing on entities with valuable data or assets where disruption can yield significant ransoms.

Enhanced Description

Snatch operates as a ransomware group employing infection methods that exploit system vulnerabilities by rebooting computers into Safe Mode. This technique allows the malware to execute without triggering standard security measures, facilitating file encryption across affected systems. The group utilizes common packers like UPX to obfuscate its payload, making it harder for detection mechanisms to identify malicious code. Snatch's operations are characterized by high-volume campaigns targeting a broad range of industries and geographies, reflecting a strategic focus on maximizing加密勒索的财务回报. Although their primary method involves direct encryption upon infection, the group remains active in evolving tactics to enhance profitability and evade defensive measures.

Key Capabilities

  • Ransomware development
  • Malware infection techniques
  • Encryption of files during Safe Mode
  • Use of packers to avoid detection

MITRE ATT&CK Tactics

Exfiltration
Encryption

ATT&CK Techniques

T1070.001
T1566.001
T1003.001

Software / Tooling

UPX (packer)
Ransomware payload

Campaigns & Victims

Snatch's campaigns are characterized by high volume, targeting numerous victims across various industries. The group demonstrates a preference for infecting systems in Safe Mode to avoid detection and maximize operational success. Notable operations include large-scale encryption attacks, focusing on sectors where data value is high to extract maximum ransom.

IOC Patterns

  • Malicious file creation during Safe Mode
  • Network communication patterns indicative of command-and-control (C2) infrastructure

Recommended Actions

  • Implement multi-factor authentication (MFA) for critical systems
  • Monitor network traffic for signs of encryption activities
  • Regularly back up critical data and segregate backup servers
  • Patch systems to address known vulnerabilities promptly

Suggested Tags

Crime
Ransomware
Encryption
Packers

Confidence Assessment

Confidence in Snatch's operational details is moderate due to limited publicly available information. While their ransomware techniques and targeting methods are inferred from standard practices, specific TTPs and precise geographical or sectoral focuses remain unclear.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

3

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
Crime
Encryption
Packers

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Nov 29, 2021
Last Seen
May 15, 2024
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.