Snatch

Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 12:59:56

Targeted industries: financial-services healthcare-and-pharmaceutical professional-services technology-and-telecommunications

Context

Snatch is a ransomware family that encrypts files and demands a ransom for decryption. Known for its double-extortion tactic, it not only encrypts files but also exfiltrates data to pressure victims into paying.

Detection coverage

  • 3 YARA rules

Detection rules

  • MALPEDIA_Win_Snatch_Loader_Auto (yara-rule)
  • DITEKSHEN_MALWARE_Win_Snatch (yara-rule)
  • DITEKSHEN_INDICATOR_KB_Gobuildid_Snatch (yara-rule)

Reports & references

  • secureworks.com — Ransomware Groups Use Tor Based Backdoor For Persistent Access (report)
  • news.sophos.com — The Ransomware Threat Intelligence Center (report)
  • cyborgsecurity.com — Hunting Ransomware Inhibiting System Backup Or Recovery (report)
  • t.me — Snatch News (report)
  • blog.intel471.com — A Brief History Of Ta505 (report)
  • github.com — Snatch.Md (report)
  • intel471.com — A Brief History Of Ta505 (report)
  • news.sophos.com — Snatch Ransomware Reboots Pcs Into Safe Mode To Bypass Protection (report)
  • thedfirreport.com — Snatch Ransomware (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • twitter.com — 1191414501297528832 (report)
  • bleepingcomputer.com — Snatch Ransomware Reboots To Windows Safe Mode To Bypass Av Tools (report)
  • CrowdStrike — Financial Motivation Drives Golang Malware Adoption (report)
  • ransomlook.io — Snatch (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Snatch (report)

External references