Snatch — Ransomware Profile

Snatch is active since 2018, known for rebooting Windows into Safe Mode to bypass security before encryption. Joint CISA/FBI advisory AA23-263A. Also acts as data broker purchasing stolen data from other groups. Targets defense, food/agriculture, and IT sectors.

Also tracked as

Snatch Team

Tools & malware

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions