Snatch — Ransomware Profile
Snatch is active since 2018, known for rebooting Windows into Safe Mode to bypass security before encryption. Joint CISA/FBI advisory AA23-263A. Also acts as data broker purchasing stolen data from other groups. Targets defense, food/agriculture, and IT sectors.Also tracked as
Snatch Team
Tools & malware
- Cobalt Strike Command and Control
- Metasploit Exploitation
- PsExec Lateral Movement
- Snatch Encryptor Ransomware
Recent claimed victims
- Neovia 2024-05-16
- UK government 2024-05-01
- The Royal Family of Great Britain 2024-04-16
- Miki Travel Limited 2024-03-27
- Retirement Line 2024-03-19
- Butler, Lavanceau & Sober 2024-03-18
- Dörr Group 2024-03-13
- Seven Seas Group 2024-03-05
- HSPG & Associates 2024-02-29
- Frencken 2024-02-28
- Hawbaker Engineering 2024-02-15
- US government (private data) +Rothschild&Rockefeller 2024-01-26
- US government (private data) 2024-01-24
- Charm Sciences 2024-01-13
- Malabar Gold & Diamonds 2024-01-13
- Banco Promerica 2024-01-13