Skip to content
CTI Academy Sponsor CTI Academy
Ransomware group

Snatch ransomware

16 victims listed on the Snatch leak site across 8 countries. Most recent disclosure .

Victims
16
0.1% of all tracked
Countries
8
Most: United States
Sectors
7
Most: Public Sector
First seen
Jan 2024
In this database

ThreatAI analysis

Compiled from the ransomware.live profile for Snatch and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Who Snatch is

Snatch is a ransomware which infects victims by rebooting the PC into Safe Mode. Most of the existing security protections do not run in Safe Mode so that it the malware can act without expected countermeasures and it can encrypt as many files as it finds. It uses common packers such as UPX to hide its payload.

Recorded activity

Disclosures attributed to Snatch in this database run from January 2024 to May 2024, totalling 16 victims — 0.1% of everything tracked here. Snatch has listed victims in 8 countries in this database, most often United States, followed by United Kingdom and India. The sectors appearing most in its listings are Public Sector, Business Services, Transportation/Logistics.

Tooling observed in Snatch operations

  • BCDEdit
  • Cobalt Strike
  • Meterpreter

Software reported in use by Snatch. Most are legitimate administration or transfer utilities; their presence in an environment is a signal to investigate, not proof of compromise.

Indicators of compromise

Showing a sample of 2 EMAIL on file. Hashes and network indicators published for Snatch. Leak-site addresses are deliberately excluded. Indicators age quickly — treat a match as a starting point for investigation, and an absence of matches as no assurance.

YARA detection rules

snatch.yar
import "pe"

rule snatch_ransomware_x3_loader {
	meta:
		description = "snatch-ransomware - file x3.exe"
		author = "DFIR Report"
		reference = "https://thedfirreport.com/"
		date = "2020-06-17"
		hash1 = "b9e4299239880961a88875e1265db0ec62a8c4ad6baf7a5de6f02ff4c31fcdb1"
	strings:
		$s1 = "jd4ob7162ns.dll" wide fullword
		$s2 = "kb05987631s.dll" wide fullword
		$s3 = "fw0a53482aa.dll" wide fullword
		$s4 = "C:\\Builds\\TP\\rtl\\common\\TypInfo.pas" wide fullword
		$s5 = "C:\\Builds\\TP\\rtl\\sys\\SysUtils.pas" wide fullword
		$s6 = "C:\\Builds\\TP\\rtl\\common\\Classes.pas" wide fullword
		$s7 = "/K schtasks /Create /RU SYSTEM /SC DAILY /ST 00:00 /TN \"Regular Idle Maintenance\" /TR \"" wide fullword
		$s8 = "/K schtasks /Create /RU SYSTEM /SC ONSTART /TN \"Regular Idle Maintenances\" /TR \"" wide fullword
		$s9 = "RootP0C" ascii fullword
		$s10 = "Component already destroyed: " wide fullword
		$s11 = "Stream write error The specified file was not found2Length of Strings and Objects arrays must be equal#''%s'' is not a valid int" wide
		$s12 = "PPackageTypeInfo$\"@" ascii fullword
		$s13 = "PositionP0C" ascii fullword
		$s14 = "DesignInfoP0C" ascii fullword
		$s15 = "OwnerP0C" ascii fullword
		$s16 = "3\"4\\4~4" ascii fullword
		$s17 = "TComponentClassP0C" ascii fullword
		$s18 = ":$:2:6:L:\\:l:t:x:|:" ascii fullword
		$s19 = ":P:T:X:\\:t:" ascii fullword
		$s20 = ":,:<:@:L:T:X:\\:`:d:h:l:p:t:x:|:" ascii fullword
	condition:
		uint16(0) == 0x5a4d and filesize < 900KB and (pe.imphash() == "d6136298ea7484a715d40720221233be" or 8 of them)
}


rule snatch_ransomware_safe_go_ransomware {
	meta:
		description = "snatch-ransomware - file safe.exe"
		author = "DFIR Report"
		reference = "https://thedfirreport.com/"
		date = "2020-06-17"
		hash1 = "3160b4308dd9434ebb99e5747ec90d63722a640d329384b1ed536b59352dace6"
	strings:
		$s1 = "dumpcb" ascii fullword
		$s2 = "dfmaftpgc" ascii fullword
		$s3 = "ngtrunw" ascii fullword
		$s4 = "_dumpV" ascii fullword
		$s5 = ".dll3u^" ascii fullword
		$s6 = "D0s[Host#\"0" ascii fullword
		$s7 = "CPUIRC32D,OPg" ascii fullword
		$s8 = "WSAGetOv" ascii fullword
		$s9 = "Head9iuA" ascii fullword
		$s10 = "SpyL]ZIo" ascii fullword
		$s11 = "cmpbody" ascii fullword
		$s12 = "necwnamep" ascii fullword
		$s13 = "ZonK+ pW" ascii fullword
		$s14 = "printabl" ascii fullword
		$s15 = "atomicn" ascii fullword
		$s16 = "powrprof" ascii fullword
		$s17 = "recdvoc" ascii fullword
		$s18 = "nopqrsx" ascii fullword
		$s19 = "ghijklm" ascii fullword
		$s20 = "spdelta" ascii fullword
	condition:
		uint16(0) == 0x5a4d and filesize < 8000KB and (pe.imphash() == "6ed4f5f04d62b18d96b26d6db7c18840" or 8 of them)
}

Community-contributed rules for Snatch, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat actor analysis

Snatch has disclosed 16 victims on its leak site, 0.1% of all ransomware listings tracked in this database. Its earliest disclosure here dates to January 2024.

The group has listed organisations in 8 countries, most often in United States (6 victims), followed by United Kingdom, India, France.

By industry, its listings concentrate in Public Sector, Business Services, Transportation/Logistics — sectors that hold sensitive data or cannot tolerate long outages, both of which raise the pressure to pay.

Like most current ransomware operations, Snatch is likely to use double extortion: data is stolen before files are encrypted, and organisations that refuse to pay are named on the leak site with the stolen data as leverage.

Snatch victims 16

Organization Disclosed
Neovia
FRFrance
UK government
GBUnited Kingdom
The Royal Family of Great Britain
GBUnited Kingdom
Miki Travel Limited
GBUnited Kingdom
Retirement Line
GBUnited Kingdom
Butler, Lavanceau & Sober
USUnited States
Dörr Group
DEGermany
Seven Seas Group
AEUAE
HSPG & Associates
USUnited States
Frencken
MYMalaysia
Hawbaker Engineering
USUnited States
US government (private data) +Rothschild&Rockefeller
USUnited States
US government (private data)
USUnited States
Banco Promerica
CRCosta Rica
Charm Sciences
USUnited States
Malabar Gold & Diamonds
INIndia

Frequently asked questions

What is Snatch ransomware?

Snatch is a ransomware threat group that has claimed 16 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Snatch attacked?

Snatch has claimed 16 victims in our database, representing 0.1% of all tracked ransomware attacks. The most targeted countries are United States, United Kingdom, India, France.

Which countries does Snatch target?

Snatch has attacked organizations in 8 countries. The top targeted countries are: United States, United Kingdom, India, France.

Which industries does Snatch target?

Snatch most frequently targets the Public Sector, Business Services, Transportation/Logistics sectors based on victim disclosures in our database.

Is Snatch still active?

Snatch's most recent victim disclosure in our database was on May 16, 2024. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.