Snatch is a human-operated ransomware family and associated extortion operation active since at least 2018, known for rebooting compromised Windows systems into Safe Mode before encrypting files. This technique is used to evade endpoint protection and other security tools that commonly do not run in Safe Mode. The malware installs itself as a Windows service capable of starting in Safe Mode, modifies boot configuration to force a Safe Mode restart, deletes Volume Shadow Copies, and then encrypts local data while preserving enough system stability for the attack to complete.
Snatch intrusions have been associated with opportunistic enterprise targeting in the United States, Canada, and multiple European countries. Reported access vectors include brute-force attacks against exposed remote administration services, especially RDP, and affiliate-supplied access through channels such as VNC, TeamViewer, web shells, or SQL injection into corporate environments. Operators have been observed maintaining access for days to weeks before ransomware deployment, using reconnaissance commands, credential theft from LSASS, network discovery, and lateral movement to expand control across victim networks.
The operation has also been linked to data theft and double-extortion tactics. In addition to file encryption, Snatch operators have used separate tooling for surveillance and exfiltration, uploaded stolen victim data, and publicly pressured non-paying organizations through leak-site activity. Snatch is regarded as an early adopter of the naming-and-shaming model in ransomware extortion. Reporting has also noted possible affiliate overlap or tradecraft sharing with other ransomware ecosystems, though such relationships are not always attributable with high confidence.
Observed Snatch tooling has included the ransomware payload itself, a separate data-stealing component, Cobalt Strike for post-compromise access, and legitimate administrative utilities used to disable defenses and support remote execution. Samples have been described as Go-based and packed for obfuscation. Snatch has also been reported to use Linux variants in some attacks, indicating expansion beyond Windows-only operations, although its most distinctive and best-documented behavior remains Safe Mode encryption on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The first of these tools was named decrypt.py ... and is used for decrypting password data from Fortinet devices vulnerable to CVE-2019-6693... Unlike decrypt.py, this tool chains CVE-2019-6693 and CVE-2022-40684 in order to increase the effectiveness of exploitation.
The other tool identified for exploitation of Fortinet devices was named fortiConfParser.py ... This Python script is used for remotely extracting the configuration of Fortinet devices, using a publicly known authentication bypass (CVE-2022-40684) ... Unlike decrypt.py, this tool chains CVE-2019-6693 and CVE-2022-40684 in order to increase the effectiveness of exploitation.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For example, in 2017 TA505 (also known as G0092, GOLD TAHOE) began using GlobeImposter in replacement of Jaff, GandCrab, and Snatch to extend the reach and effectiveness of their campaigns.
For example, in 2017 TA505 (also known as G0092, GOLD TAHOE) began using GlobeImposter in replacement of Jaff, GandCrab, and Snatch to extend the reach and effectiveness of their campaigns.
The ransomware, which calls itself Snatch, sets itself up as a service that will run during a Safe Mode boot. It quickly reboots the computer into Safe Mode... Snatch encrypts the victims’ hard drives.
The actor frequently, but not always, uses one or more intermediate downloader, such as an as yet unnamed PowerShell script, sLoad, Snatch, or Godzilla.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
then runs a batch file (also located in the temp directory) that uploads the tasklist file to the C2 server.
Using the Azure server as a foothold, the attackers leveraged that administrator’s account to log into a domain controller (DC) machine on the same network, and then performed surveillance tasks on the target’s network over the course of several weeks.
The malware then adds this key to the Windows registry so it will start up during a Safe Mode boot. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SuperBackupMan:Default:Service
Looking for affiliate partners with access to RDP\VNC\TeamViewer\WebShell\SQL inj [SQL injection] in corporate networks...
The samples we’ve seen are also packed with the open source packer UPX to obfuscate their contents.
Using the Azure server as a foothold, the attackers leveraged that administrator’s account to log into a domain controller (DC) machine on the same network, and then performed surveillance tasks on the target’s network over the course of several weeks.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
The attackers also installed a free Windows utility called Advanced Port Scanner and used that tool to discover additional machines on the network they could target.
The attackers query the list of users authorized to log in on the box, and write the results to a file.
The attackers also installed a free Windows utility called Advanced Port Scanner and used that tool to discover additional machines on the network they could target.
These services have long randomized filenames, such as this one, which queries the list of running processes from the tasklist program, outputs it to a file in the temp directory, then runs a batch file...
We also observed them dump WMIC system & user data, process lists, and even the memory contents of the Windows LSASS service, to a file.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
The attackers initially accessed the company’s internal network by brute-forcing the password to an administrator’s account on a Microsoft Azure server, and were able to log in to the server using Remote Desktop (RDP).
The attackers initially accessed the company’s internal network by brute-forcing the password to an administrator’s account on a Microsoft Azure server, and were able to log in to the server using Remote Desktop (RDP).
本動画ではSnatchランサムウェアの感染の様子や、セーフモードでの暗号化に至るまでに具体的にどのような挙動を行うのか、またセーフモードで暗号化される事がどのような脅威となり得るのかについて解説しています。
When the computer comes back up after the reboot, this time in Safe Mode, the malware uses the Windows component net.exe to halt the SuperBackupMan service... net stop SuperBackupMan
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family mentioned as a prior example of abusing Safe Mode to impair defenses before encryption.
Referenced as another ransomware family known for using Safe Mode tactics to impair defenses.
Referenced as another ransomware family known for using Safe Mode tactics to disable defenses before encryption.
Referenced as an older ransomware family associated with Safe Mode reboot tactics to evade security tooling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.