01
Snatch is tracked as an affiliate-enabled ransomware service.1
The brand supplies shared capabilities, but affiliates can change access methods and tooling; incident scoping should follow observed behavior rather than assume one fixed playbook.
CARDS
Snatch is a financially motivated ransomware group operating a ransomware-as-a-service (RaaS) model since its emergence in 2018, initially known as Team Truniger. The group is notable for its unique defense evasion technique that involves rebooting compromised systems into Windows Safe Mode to bypass endpoint security software before encrypting data. Snatch employs a double extortion scheme, encrypting victim data and exfiltrating sensitive information, which they threaten to publish on their data leak site if ransom demands are not met. The group has adapted its tactics since mid-2021, leveraging successes from other ransomware variants and even purchasing previously stolen data to further pressure victims into paying. Snatch is assessed with high confidence to be of Russian origin, with command and control infrastructure often hosted on Russian bulletproof hosting services. The group sometimes lists victims alongside those of other ransomware gangs like Nokoyawa and Conti on its extortion blog, indicating a complex ecosystem of data monetization.
Directory Briefing
01
The brand supplies shared capabilities, but affiliates can change access methods and tooling; incident scoping should follow observed behavior rather than assume one fixed playbook.
02
The retained behavior points to credentials, remote access, phishing, or exposed services; preserve authentication, VPN, edge-device, email, and remote-administration evidence together.
03
Check for earlier credential use, remote sessions, administrative changes, and data access because public actor records often understate the full pre-impact timeline.
04
Evidence includes credential or account abuse; response should cover privileged, service, remote-access, SaaS, and recovery identities—not just interactive user passwords.
05
Lateral movement, administrative access, and shared server infrastructure can turn a limited foothold into broad business interruption.
06
Reported tooling or behavior includes PowerShell, remote execution, or other dual-use administration behavior; detection must distinguish authorized administration from anomalous context and sequence.
07
Defense impairment or evidence removal is retained in the source record. Protect immutable backups and investigate access to recovery systems before trusting them.
08
Collection or exfiltration behavior includes data staging and exfiltration; counsel and forensics need a shared record of what was accessed, staged, and transferred.
09
Retained targeting includes Construction of Buildings, Food Manufacturing, Other Information Services, Software Publishers, and Real Estate across United Arab Emirates, Afghanistan, Austria, and Australia; translate those sectors into the organization's exposed systems and high-value data.
10
Align counsel, forensics, identity, recovery, insurance, communications, and regulatory analysis around one compromise timeline and one evidence-preservation plan.
Bottom Line Up Front
The brand supplies shared capabilities, but affiliates can change access methods and tooling; incident scoping should follow observed behavior rather than assume one fixed playbook.
The retained behavior points to credentials, remote access, phishing, or exposed services; preserve authentication, VPN, edge-device, email, and remote-administration evidence together.
Check for earlier credential use, remote sessions, administrative changes, and data access because public actor records often understate the full pre-impact timeline.
Evidence includes credential or account abuse; response should cover privileged, service, remote-access, SaaS, and recovery identities—not just interactive user passwords.
Lateral movement, administrative access, and shared server infrastructure can turn a limited foothold into broad business interruption.
Reported tooling or behavior includes PowerShell, remote execution, or other dual-use administration behavior; detection must distinguish authorized administration from anomalous context and sequence.
Defense impairment or evidence removal is retained in the source record. Protect immutable backups and investigate access to recovery systems before trusting them.
Collection or exfiltration behavior includes data staging and exfiltration; counsel and forensics need a shared record of what was accessed, staged, and transferred.
Retained targeting includes Construction of Buildings, Food Manufacturing, Other Information Services, Software Publishers, and Real Estate across United Arab Emirates, Afghanistan, Austria, and Australia; translate those sectors into the organization's exposed systems and high-value data.
Align counsel, forensics, identity, recovery, insurance, communications, and regulatory analysis around one compromise timeline and one evidence-preservation plan.
Decision Context
Snatch is a financially motivated ransomware group operating a ransomware-as-a-service (RaaS) model since its emergence in 2018, initially known as Team Truniger. The group is notable for its unique defense evasion technique that involves rebooting compromised systems into Windows Safe Mode to bypass endpoint security software before encrypting data. Snatch employs a double extortion scheme, encrypting victim data and exfiltrating sensitive information, which they threaten to publish on their data leak site if ransom demands are not met. The group has adapted its tactics since mid-2021, leveraging successes from other ransomware variants and even purchasing previously stolen data to further pressure victims into paying. Snatch is assessed with high confidence to be of Russian origin, with command and control infrastructure often hosted on Russian bulletproof hosting services. The group sometimes lists victims alongside those of other ransomware gangs like Nokoyawa and Conti on its extortion blog, indicating a complex ecosystem of data monetization.1,2
Actor Card Detail
Victimology
No named victim organizations are retained in the cited source artifacts for this profile. Countries and sectors are targeting context, not victim identities.
Identity
Aliases1
Source Boundary
SOCRadar is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Target Countries / Exposure1,2
Associated Activity1
ATT&CK IDs1
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| snatch Ransomware / Extortion Operations4 | snatch Ransomware / Extortion Operations is retained in the campaign database for snatch. Snatch is a ransomware which infects victims by rebooting the PC into Safe Mode. Most of the existing security protections do not run in Safe Mode so that it the malware can act without expected countermeasures and it can encrypt as many files as it finds. It uses common packers such as UPX to hide its payload. |
Indicators
SOCRadar reports 15363 IOCs for this profile. IntelliOS currently retains 59 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 2 source groups tracked; 1 currently contributes retained observable or context rows.
Retained Observables
Showing 59 of 59
| Type | Value | Source |
|---|---|---|
| SHA-256 Hash | 0965CB8EE38ADEDD9BA06BDAD9220A35890C2DF0E4C78D0559CD6DA653BF740F3 | CISA AA23-263A |
| SHA-256 Hash | 1FBDB97893D09D59575C3EF95DF3C929FE6B6DDF1B273283E4EFADF94CDC802D3 | CISA AA23-263A |
| SHA-256 Hash | 2155A029A024A2FFA4EFF9108AC15C7DB527CA1C8F89CCFD94CC3A70B77CFC573 | CISA AA23-263A |
| SHA-256 Hash | 251427C578EAA814F07037FBE6E388B3BC86ED3800D7887C9D24E7B94176E30D3 | CISA AA23-263A |
| SHA-256 Hash | 28E82F28D0B9EB6A53D22983E21A9505ADA925EBB61382FABEBD76B8C4ACFF7C3 | CISA AA23-263A |
| SHA-256 Hash | 3295F5029F9C9549A584FA13BC6C25520B4FF9A4B2FEB1D9E935CC9E4E0F09243 | CISA AA23-263A |
| SHA-256 Hash | 510E9FA38A08D446189C34FE6125295F410B36F00ACEB65E7B4508E9D7C4E1D13 | CISA AA23-263A |
| SHA-256 Hash | 5950B4E27554585123D7FCA44E83169375C6001201E3BF26E57D079437E70BCD3 | CISA AA23-263A |
| SHA-256 Hash | 6992AAAD3C47B938309FC1E6F37179EB51F028536F8AFC02E4986312E29220C03 | CISA AA23-263A |
| SHA-256 Hash | 6C9D8C577DDDF9CC480F330617E263A6EE4461651B4DEC1F7215BDA77DF911E73 | CISA AA23-263A |
| SHA-256 Hash | 7018240D67FD11847C7F9737EAAAE45794B37A5C27FFD02BEAACAF6AE13352B33 | CISA AA23-263A |
| SHA-256 Hash | 84E1476C6B21531DE62BBAC67E52AB2AC14AA7A30F504ECF33E6B62AA33D1FE53 | CISA AA23-263A |
| SHA-256 Hash | A201F7F81277E28C0BDD680427B979AEE70E42E8A98C67F11E7C83D02F8FE7AE3 | CISA AA23-263A |
| SHA-256 Hash | A80C7FE1F88CF24AD4C55910A9F2189F1EEDAD25D7D0FD53DBFE6BDD68912A843 | CISA AA23-263A |
| SHA-256 Hash | B998A8C15CC19C8C31C89B30F692A40B14D7A6C09233EB976C07F19A84ECCB403 | CISA AA23-263A |
| SHA-256 Hash | ED0FD61BF82660A69F5BFE0E66457CFE56D66DD2B310E9E97657C37779AEF65D3 | CISA AA23-263A |
| SHA-256 Hash | FC31043B5F079CE88385883668EEEBBA76A62F77954A960FB03BF46F47DBB0663 | CISA AA23-263A |
| MD5 Hash | 2202E846BA05D7F0BB20ADBC5249C3593 | CISA AA23-263A |
| MD5 Hash | 304F8F54FB79BB470F3CCDDD2BEFC5DA3 | CISA AA23-263A |
| MD5 Hash | 395DAD45C4761490C6480308A8359C063 | CISA AA23-263A |
| MD5 Hash | 3A24A7B7C1BA74A5AFA50F88BA81D5503 | CISA AA23-263A |
| MD5 Hash | 3D29E9CDD2A9D76E57E8A3F9E6ED36433 | CISA AA23-263A |
| MD5 Hash | 3D33A19BB489DD5857B515882B43DE123 | CISA AA23-263A |
| MD5 Hash | 3E36D3DC132E3A076539ACC9FCD5535C3 | CISA AA23-263A |
| MD5 Hash | 54FE4D49D7B4471104C897F187E07F913 | CISA AA23-263A |
| MD5 Hash | 55310BB774FFF38CCA265DBC70AD67053 | CISA AA23-263A |
| MD5 Hash | 6D9D31414EE2C175255B092440377A883 | CISA AA23-263A |
| MD5 Hash | 891708936393B69C212B97604A982FED3 | CISA AA23-263A |
| MD5 Hash | C95C81CA4E6B8153B458D29186E696BC3 | CISA AA23-263A |
| MD5 Hash | F9BF364F42F6E4D4BDC2CAE74D6CA4CC3 | CISA AA23-263A |
| Filename | bsfyqgqeauegwyfvtp.bat3 | CISA AA23-263A |
| Filename | DefenderControl.exe3 | CISA AA23-263A |
| Filename | eqbglqcngblqnl.bat3 | CISA AA23-263A |
| Filename | evhgpp.bat3 | CISA AA23-263A |
| Filename | ghnhfglwaplf.bat3 | CISA AA23-263A |
| Filename | nllraq.bat3 | CISA AA23-263A |
| Filename | PRETTYOCEANApplicationdrs.bi3 | CISA AA23-263A |
| Filename | pxyicmajjlqrtgcnhi.bat3 | CISA AA23-263A |
| Filename | rgibdcghzwpk.bat3 | CISA AA23-263A |
| Filename | safe.exe3 | CISA AA23-263A |
| Filename | Setup.exe3 | CISA AA23-263A |
| Filename | WRSA.exe3 | CISA AA23-263A |
| Filename | ygariiwfenmqteiwcr.bat3 | CISA AA23-263A |
| File Path | C:\$SysReset3 | CISA AA23-263A |
| File Path | UsersmcsadminDesktopDefenderControl.exe3 | CISA AA23-263A |
| Network Indicator | airmail.cc3 | CISA AA23-263A |
| Network Indicator | cock.li3 | CISA AA23-263A |
| Network Indicator | sezname.cz3 | CISA AA23-263A |
| Email Address | datasto100@tutanota.com3 | CISA AA23-263A |
| Email Address | funny385@proton.me3 | CISA AA23-263A |
| Email Address | funny385@swisscows.email3 | CISA AA23-263A |
| Email Address | mailz13morales@proton.me3 | CISA AA23-263A |
| Email Address | russellrspeck@protonmail.com3 | CISA AA23-263A |
| Email Address | russellrspeck@seznam.cz3 | CISA AA23-263A |
| Email Address | sn.tchnews.top@protonmail.me3 | CISA AA23-263A |
| Email Address | snatch.vip@protonmail.com3 | CISA AA23-263A |
| Mutex | gcc-hmem-tdm2-sjlj_once3 | CISA AA23-263A |
| Mutex | gcc-shmem-tdm2-fc_key3 | CISA AA23-263A |
| Mutex | gcc-shmem-tdm2-use_fc_key3 | CISA AA23-263A |
Actor Chronology
No source-backed actor-activity dates are currently retained. Publication and record-maintenance dates are not promoted into activity dates.
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Snatch | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | Snatch | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Snatch.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Threat actor directory source for profile fields and reported activity. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/snatch | Actor-specific source for ransomware profile metadata and reported IOC counts when available. |
| 3 | CISA AA23-263A: StopRansomware Snatch Ransomware https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-263a | IOC Source |
| 4 | snatch - Ransomware.live group profile https://www.ransomware.live/group/snatch | Ransomware.live campaign row source for snatch Ransomware / Extortion Operations. |