Snatch
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 12:59:56
Targeted industries: financial-services healthcare-and-pharmaceutical professional-services technology-and-telecommunications
Context
Snatch is a ransomware family that encrypts files and demands a ransom for decryption. Known for its double-extortion tactic, it not only encrypts files but also exfiltrates data to pressure victims into paying.
Detection coverage
- 3 YARA rules
Detection rules
- MALPEDIA_Win_Snatch_Loader_Auto (yara-rule)
- DITEKSHEN_MALWARE_Win_Snatch (yara-rule)
- DITEKSHEN_INDICATOR_KB_Gobuildid_Snatch (yara-rule)
Reports & references
- secureworks.com — Ransomware Groups Use Tor Based Backdoor For Persistent Access (report)
- news.sophos.com — The Ransomware Threat Intelligence Center (report)
- cyborgsecurity.com — Hunting Ransomware Inhibiting System Backup Or Recovery (report)
- t.me — Snatch News (report)
- blog.intel471.com — A Brief History Of Ta505 (report)
- github.com — Snatch.Md (report)
- intel471.com — A Brief History Of Ta505 (report)
- news.sophos.com — Snatch Ransomware Reboots Pcs Into Safe Mode To Bypass Protection (report)
- thedfirreport.com — Snatch Ransomware (report)
- ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
- twitter.com — 1191414501297528832 (report)
- bleepingcomputer.com — Snatch Ransomware Reboots To Windows Safe Mode To Bypass Av Tools (report)
- CrowdStrike — Financial Motivation Drives Golang Malware Adoption (report)
- ransomlook.io — Snatch (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Snatch (report)