SnapMC is a data-theft extortion threat actor known for rapid, encryption-less intrusions that typically prioritize stealing data and coercing payment through leak threats rather than deploying file-encrypting ransomware. The actor has not been publicly linked at high confidence to any previously known intrusion set. SnapMC is named for the speed of its operations—often completed in under 30 minutes—and for its use of the MinIO client in exfiltration workflows. SnapMC has been observed targeting vulnerable internet-facing web applications and VPN solutions, including exploitation of Telerik UI for ASPX.NET vulnerabilities such as CVE-2019-18935 and SQL injection weaknesses. Its operations include scanning and external attack-surface discovery, exploitation of public-facing applications, establishment of reverse-shell access, and use of PowerShell for hands-on reconnaissance. Observed reconnaissance has included user, privilege, and disk enumeration. In most reported cases the actor did not rely on privilege escalation, though at least one intrusion involved attempted escalation using publicly available PowerShell-based tooling. For collection and exfiltration, SnapMC has used SQL query tooling to access databases, export records to CSV, compress staged data with 7-Zip, and upload stolen material to cloud storage using the MinIO client. The actor’s extortion model is centered on proof-of-theft and pressure tactics: victims receive emails containing evidence of stolen data, short response deadlines, and threats to publish the data or contact customers and media outlets if negotiations do not proceed. This places SnapMC among early adopters of pure extortion or data-breach extortion operations, sometimes described as encryption-less ransomware, where the coercive leverage comes from exfiltration and disclosure threats rather than system encryption or operational disruption.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Identified as an early group associated with encryption-less or extortion-only ransomware activity.
SnapMC is an adversary group observed conducting rapid data breach extortion attacks, stealing data and threatening to publish it if a ransom is not paid, typically without deploying ransomware.
Conducting rapid data-breach extortion intrusions focused on stealing data and threatening publication rather than deploying ransomware or disrupting operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.