Netskope Threat Labs

Snatch

ATP Sandbox Adv. HeuristicsAV

Snatch is ransomware that targets Windows systems, encrypts files, and demands payment for decryption, and its operators pioneered rebooting infected servers into safe mode to bypass endpoint security. Its affiliates exfiltrate data before encryption and pressure victims through a leak site, and campaigns have hit organizations across Europe and North America. The safe mode technique, which blinds many security agents at boot, remains its most distinctive behavior.

First seen
May 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Ransomware.Snatch
Dump:Generic.Ransom.Snatch.AD012E21
Gen:Variant.Ransom.Snatch.1
Gen:Variant.Ransom.Snatch.12
Gen:Variant.Ransom.Snatch.9
Generic.Ransom.Snatch.0122AE6C
Generic.Ransom.Snatch.0ACDCBD3
Generic.Ransom.Snatch.1A12DF23
Generic.Ransom.Snatch.22D4464C
Generic.Ransom.Snatch.26EF41A1