Snatch is a Windows ransomware family and ransomware-as-a-service operation active since at least 2018. It is notable for rebooting compromised systems into Windows Safe Mode before encryption so that many endpoint protection products and other third-party security services do not start, improving the malware’s chances of running unimpeded. The ransomware installs itself as a Windows service configured to execute during Safe Mode boot, modifies boot settings to force a Safe Mode restart, and then encrypts files after the system comes back up. Reported tradecraft also includes deletion of Volume Shadow Copies to hinder recovery.
Snatch intrusions have been associated with double extortion, combining file encryption with theft of victim data and threats to publish stolen information. Operators have been observed conducting extended pre-encryption activity over days or weeks, including reconnaissance, credential theft, lateral movement, and exfiltration. Documented tooling in Snatch-related compromises includes custom collection utilities, Cobalt Strike, and legitimate administrative or dual-use tools used for remote execution, discovery, and disabling security products.
Observed initial access has commonly involved brute forcing internet-exposed Remote Desktop services, and operators have advertised interest in other enterprise access vectors such as remote administration tools, web shells, and SQL injection. Snatch activity has affected organizations across multiple sectors and geographies, including enterprises in North America and Europe. The operation has been linked to a self-described “Snatch Team,” and U.S. government agencies have issued joint guidance on the group’s ransomware-as-a-service activity. Snatch is also recognized as an early adopter of data theft plus encryption extortion tactics.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Get2 was, in turn, observed downloading FlawedGrace, FlawedAmmyy, Snatch, and SDBbot (a new RAT) as secondary payloads.
The ransomware, which calls itself Snatch, sets itself up as a service that will run during a Safe Mode boot. It quickly reboots the computer into Safe Mode, and in the rarefied Safe Mode environment, where most software (including security software) doesn’t run, Snatch encrypts the victims’ hard drives.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Using the Azure server as a foothold, the attackers leveraged that administrator’s account to log into a domain controller (DC) machine on the same network, and then performed surveillance tasks on the target’s network over the course of several weeks.
Snatch runs itself in an elevated permissions mode, sets registry keys that instructs Windows to run it following a Safe Mode reboot...
Looking for affiliate partners with access to RDP\VNC\TeamViewer\WebShell\SQL inj [SQL injection] in corporate networks...
The samples we’ve seen are also packed with the open source packer UPX to obfuscate their contents.
The attackers query the list of users authorized to log in on the box, and write the results to a file.
The attackers also installed a free Windows utility called Advanced Port Scanner and used that tool to discover additional machines on the network they could target.
The attackers initially accessed the company’s internal network by brute-forcing the password to an administrator’s account on a Microsoft Azure server, and were able to log in to the server using Remote Desktop (RDP).
The attackers initially accessed the company’s internal network by brute-forcing the password to an administrator’s account on a Microsoft Azure server, and were able to log in to the server using Remote Desktop (RDP).
The ransomware then begins encrypting documents on the infected machine’s local hard drive.
When the computer comes back up after the reboot, this time in Safe Mode, the malware uses the Windows component net.exe to halt the SuperBackupMan service... net stop SuperBackupMan
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another ransomware operation previously observed using Safe Mode for defense evasion.
Referenced as a ransomware family known for abusing Safe Mode to disable security tools before encryption.
Referenced as an example of a ransomware family known to use Safe Mode boot to impair defenses.
Safe Modeでシステムを再起動させ、AV/EDRが十分に動作しない状態を悪用して実行されるランサムウェアとして言及されている。
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.