Sophos reported that the Snatch ransomware operators are compromising Windows environments and rebooting infected machines into Safe Mode before encrypting files, a tactic designed to bypass many security products that do not run in that state. The malware installs itself as a Windows service named SuperBackupMan, alters Safe Mode boot settings, deletes Volume Shadow Copies, and encrypts data with a victim-specific five-character file extension.
Investigated intrusions showed the attackers gaining initial access by brute-forcing exposed remote services such as RDP, then moving laterally across enterprise networks, conducting reconnaissance, stealing data, and deploying tools including Cobalt Strike, custom malware, and legitimate administrative utilities. Sophos linked the activity to the self-described "Snatch Team" and cited signs of affiliate-style recruitment on Russian-language criminal forums, while incident data from Coveware indicated at least 12 negotiations over several months with ransom demands ranging from $2,000 to $35,000 in Bitcoin against organizations in the United States, Canada, and parts of Europe.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Sophos reported that the Snatch operators appeared to have been active since summer 2018. The report also said Sophos first encountered Snatch about a year before this publication.
Sophos published research describing Snatch ransomware's use of a Windows reboot into Safe Mode before encrypting files, a capability it assessed as newly added. The report also linked the activity to the self-described 'Snatch Team' and noted opportunistic attacks against organizations in the United States, Canada, and several European countries.
Sophos investigated a ransomware outbreak at a targeted organization in mid-October involving Snatch. In that incident, the attackers had brute-forced an administrator account on a Microsoft Azure server, moved to a domain controller, conducted weeks of reconnaissance, and deployed surveillance tooling across about 200 machines.
Coveware told Sophos it had negotiated with the Snatch actors 12 times between July and October. Reported ransom demands ranged from $2,000 to $35,000 in Bitcoin.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcembsd.jp
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.