Snatch is a financially motivated ransomware and data-extortion threat actor, also referred to as Snatch Team and associated with a ransomware-as-a-service model. The group has been active since at least 2018 and is known for intrusions that begin with brute-force attacks against internet-exposed remote access services, especially RDP, followed by prolonged hands-on-keyboard activity inside victim networks. Operators conduct reconnaissance, steal credentials, move laterally, deploy surveillance and remote administration tooling, exfiltrate data, and then execute ransomware. A defining Snatch tradecraft feature is forcing compromised Windows systems to reboot into Safe Mode before encryption in order to reduce the effectiveness of endpoint security products. The ransomware installs itself as a service configured to run in Safe Mode, modifies boot settings to trigger a Safe Mode restart, deletes shadow copies, and encrypts files after reboot. Reported operations have also involved credential theft from LSASS, Active Directory and host enumeration, internal scanning, use of PsExec for remote execution, and abuse of legitimate administrative or dual-use tools alongside frameworks such as Cobalt Strike. Snatch has been linked to both ransomware and pure data-extortion activity. The group has operated a leak site and has publicly named specific individuals as responsible for breaches to intensify pressure on victims. A 2021 intrusion against Volvo Cars was claimed by the Snatch extortion operation and involved theft and publication of research and development data. Reporting also places Snatch among ransomware groups targeting organizations in North America and Europe, and among groups that have targeted Korean companies. The operators have advertised for affiliates on Russian-language criminal forums, seeking access vectors including RDP, VNC, TeamViewer, web shells, and SQL injection, and offering infrastructure and training. Snatch has also been discussed as part of the broader Russian-language ransomware ecosystem and has been linked through infrastructure reporting to bulletproof hosting services used by cybercriminal actors. The group’s dominant motivation is financial extortion rather than espionage or disruption.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a comparison point for prior Safe Mode abuse by ransomware crews.
Referenced as a ransomware family known for using Safe Mode boot to impair defenses.
Ransomware and data extortion group whose operations were linked to Media Land bulletproof hosting infrastructure.
セーフモードを悪用してAV/EDRが動作しにくい状態でランサムウェアを実行することで知られる。
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.