Skip to content

SNATCH

Snatch is a human-operated ransomware family and associated extortion operation active since at least 2018, known for rebooting compromised Windows systems into Safe Mode before encrypting files.

Profile source: Mallory opens in a new tab

SNATCH

Family profile

Snatch is a human-operated ransomware family and associated extortion operation active since at least 2018, known for rebooting compromised Windows systems into Safe Mode before encrypting files. This technique is used to evade endpoint protection and other security tools that commonly do not run in Safe Mode. The malware installs itself as a Windows service capable of starting in Safe Mode, modifies boot configuration to force a Safe Mode restart, deletes Volume Shadow Copies, and then encrypts local data while preserving enough system stability for the attack to complete.

Snatch intrusions have been associated with opportunistic enterprise targeting in the United States, Canada, and multiple European countries. Reported access vectors include brute-force attacks against exposed remote administration services, especially RDP, and affiliate-supplied access through channels such as VNC, TeamViewer, web shells, or SQL injection into corporate environments. Operators have been observed maintaining access for days to weeks before ransomware deployment, using reconnaissance commands, credential theft from LSASS, network discovery, and lateral movement to expand control across victim networks.

The operation has also been linked to data theft and double-extortion tactics. In addition to file encryption, Snatch operators have used separate tooling for surveillance and exfiltration, uploaded stolen victim data, and publicly pressured non-paying organizations through leak-site activity. Snatch is regarded as an early adopter of the naming-and-shaming model in ransomware extortion. Reporting has also noted possible affiliate overlap or tradecraft sharing with other ransomware ecosystems, though such relationships are not always attributable with high confidence.

Observed Snatch tooling has included the ransomware payload itself, a separate data-stealing component, Cobalt Strike for post-compromise access, and legitimate administrative utilities used to disable defenses and support remote execution. Samples have been described as Go-based and packed for obfuscation. Snatch has also been reported to use Linux variants in some attacks, indicating expansion beyond Windows-only operations, although its most distinctive and best-documented behavior remains Safe Mode encryption on Windows systems.

Capabilities

  • Brute Force
  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance

Operational record

1
YARA rules
1
Ransom notes
5
Leak sites
0 available

LOLBAS

  • BCDEdit
  • ServiceControl (sc.exe)

Offsec

  • Cobalt Strike
  • Meterpreter

Reported operators

Threat actors

4 named in public reporting
G0092

For example, in 2017 TA505 (also known as G0092, GOLD TAHOE) began using GlobeImposter in replacement of Jaff, GandCrab, and Snatch to extend the reach and effectiveness of their campaigns.

TA505

For example, in 2017 TA505 (also known as G0092, GOLD TAHOE) began using GlobeImposter in replacement of Jaff, GandCrab, and Snatch to extend the reach and effectiveness of their campaigns.

Snatch

The ransomware, which calls itself Snatch, sets itself up as a service that will run during a Safe Mode boot. It quickly reboots the computer into Safe Mode... Snatch encrypts the victims’ hard drives.

TA554

The actor frequently, but not always, uses one or more intermediate downloader, such as an as yet unnamed PowerShell script, sLoad, Snatch, or Godzilla.

Exploited software

Vulnerabilities linked to SNATCH

2 CVEs

MITRE ATT&CK

SNATCH in ATT&CK

32 distinct techniques

Reporting

Research mentioning SNATCH

Aug 12
Register Security

Akira ransomware scum blocked victim's security tools - and broke their own encryptor

An Akira ransomware affiliate breached a victim through a SonicWall SSL VPN account that lacked MFA after a credential-spraying attempt, then used RDP and Active Directory enumeration to map the environment, collect data, and stage exfiltration. Huntress reported the attacker created AdUsers.txt and AdComp.txt with PowerShell-based AD dumps, used WinRAR to package files, s5cmd to move data to S3, and installed AnyDesk for persistent remote access and payload delivery before launching the Akira encryptor. The intrusion’s notable defense-evasion step was forcing a compromised Windows host to reboot into Safe Mode with Networking, a technique tracked by MITRE ATT&CK as T1688, to disable endpoint protections while preserving connectivity. In Safe Mode, the Huntress agent and Microsoft Defender real-time protection were suppressed, but the Akira encryptor appears to have hit virtual-memory errors and failed to complete encryption; Defender later detected akira.exe yet could not quarantine it until the system returned to normal mode. Researchers warned the failure was accidental rather than protective, and urged organizations to enforce MFA on VPN access and monitor for failed VPN login bursts, Safe Mode boot changes, and unexpected security-service stoppages.

Aug 12
Huntress

Akira Hits Safe Mode: Ransomware Rebooting Around EDR | Huntress

Jul 17
Sentinelone Labs

Maze Ransomware Update: Extorting and Exposing Victims - SentinelLabs

Maze emerged as one of the most influential ransomware operations targeting businesses, corporations, and municipal organizations, combining file encryption with data theft and public leak threats to force victims into paying. The group first spread through exploit kits and malicious spam, then shifted to more targeted intrusions using spear-phishing, exploitation of internet-facing services such as Citrix ADC/NetScaler and Pulse Secure VPN, and attacks against weak RDP credentials. Researchers described Maze as a C/C++ Windows PE malware with obfuscation, anti-analysis features, and a layered encryption scheme that paired ChaCha with RSA-2048. The operation also expanded its influence by forming a ransomware cartel with LockBit and RagnarLocker, sharing leak infrastructure and tradecraft in a model that helped normalize double-extortion tactics across the broader ransomware ecosystem.

Apr 15
Mitre Attack Website

Safe Mode Boot, Technique T1688 - Enterprise | MITRE ATT&CK®

May 13
Securelist

Life of Maze ransomware | Securelist

Oct 1
Id Ransomware

Шифровальщики-вымогатели The Digest "Crypto-Ransomware": Maze, ChaCha

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.