EILMELDUNGEN LIVE
⚠️ Malware / Trojaner / VirenWhat If Ransomware Never Encrypts Anything?(26.08.2026 um 16:54 Uhr)
🕵️ SicherheitslückenHacking All The Devices, with AI? - Rob Allen - PSW #941(27.08.2026 um 23:00 Uhr)
⚠️ Malware / Trojaner / VirenLegitimate Tools Became Attack Tools(28.08.2026 um 00:00 Uhr)
🕵️ SicherheitslückenMy Life, AI and the Future of LiveOverflow(23.08.2026 um 19:53 Uhr)
⚠️ Malware / Trojaner / VirenHow North Korean Hackers end up in your Network(24.08.2026 um 20:30 Uhr)
🎥 Podcasts#121 Warum NIS 2 die Produktion verändert(24.08.2026 um 08:00 Uhr)
⚠️ Malware / Trojaner / VirenWhat If Ransomware Never Encrypts Anything?(26.08.2026 um 16:54 Uhr)
🕵️ SicherheitslückenHacking All The Devices, with AI? - Rob Allen - PSW #941(27.08.2026 um 23:00 Uhr)
⚠️ Malware / Trojaner / VirenLegitimate Tools Became Attack Tools(28.08.2026 um 00:00 Uhr)
🕵️ SicherheitslückenMy Life, AI and the Future of LiveOverflow(23.08.2026 um 19:53 Uhr)
⚠️ Malware / Trojaner / VirenHow North Korean Hackers end up in your Network(24.08.2026 um 20:30 Uhr)
🎥 Podcasts#121 Warum NIS 2 die Produktion verändert(24.08.2026 um 08:00 Uhr)

10 🕛 kürzlich 21 Min Lesezeit 20 Leser online ️ CVE-RADAR
0

#StopRansomware: Snatch Ransomware

Cyber Threat & Vulnerability Dossier CVSS 7.5 HIGH EPSS 96.4%
ANGRIPPSVEKTOR
💻 Lokal
AUTHENTIFIZIERUNG
🔑 Geringe Nutzerrechte nötig
SCHADENSPROFIL
RCE / Vollzugriff / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-94: Code Injection
Handlungsempfehlung: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
️ Im CVE-Radar öffnen
↗ Quelle (cisa.gov)
🔬 IoC Intelligence (17 Indikatoren erkannt)
0965cb8ee38adedd9ba06bdad9220a35890c2df0e4c78d0559cd6da653bf740f1fbdb97893d09d59575c3ef95df3c929fe6b6ddf1b273283e4efadf94cdc802d5950b4e27554585123d7fca44e83169375c6001201e3bf26e57d079437e70bcd7018240d67fd11847c7f9737eaaae45794b37a5c27ffd02beaacaf6ae13352b328e82f28d0b9eb6a53d22983e21a9505ada925ebb61382fabebd76b8c4acff7cfc31043b5f079ce88385883668eeebba76a62f77954a960fb03bf46f47dbb066a201f7f81277e28c0bdd680427b979aee70e42e8a98c67f11e7c83d02f8fe7ae6992aaad3c47b938309fc1e6f37179eb51f028536f8afc02e4986312e29220c0+9 weitere
🗣️ Stimme:
📑 Inhaltsübersicht

SUMMARY


Note: This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit stopransomware.gov to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources.


The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint CSA to disseminate known ransomware IOCs and TTPs associated with the Snatch ransomware variant identified through FBI investigations as recently as June 1, 2023.


Since mid-2021, Snatch threat actors have consistently evolved their tactics to take advantage of current trends in the cybercriminal space and leveraged successes of other ransomware variants’ operations. Snatch threat actors have targeted a wide range of critical infrastructure sectors including the Defense Industrial Base (DIB), Food and Agriculture, and Information Technology sectors. Snatch threat actors conduct ransomware operations involving data exfiltration and double extortion. After data exfiltration often involving direct communications with victims demanding ransom, Snatch threat actors may threaten victims with double extortion, where the victims’ data will be posted on Snatch’s extortion blog if the ransom goes unpaid.


FBI and CISA encourage organizations to implement the recommendations in the Mitigations section of this CSA to reduce the likelihood and impact of ransomware incidents.


Download the PDF version of this report:










(XML, 79.84 KB
)










framework, version 13. See the MITRE ATT&CK Tactics and Techniques section for a table of the threat actors’ activity mapped to MITRE ATT&CK® tactics and techniques. For assistance with mapping malicious cyber activity to the MITRE ATT&CK framework, see CISA and MITRE ATT&CK’s .


First appearing in 2018, Snatch operates a ransomware-as-a-service (RaaS) model and claimed their first U.S.-based victim in 2019. Originally, the group was referred to as Team Truniger, based on the nickname of a key group member, Truniger, who previously operated as a GandCrab affiliate. Snatch threat actors use a customized ransomware variant notable for rebooting devices into Safe Mode []


Initial Access and Persistence


Snatch threat actors employ several different methods to gain access to and maintain persistence on a victim’s network. Snatch affiliates primarily rely on exploiting weaknesses in Remote Desktop Protocol (RDP) []. In some instances, Snatch affiliates have sought out compromised credentials from criminal forums/marketplaces [] and establishing connections over port 443 []. Per IP traffic from event logs provided by recent victims, Snatch threat actors initiated RDP connections from a Russian bulletproof hosting service and through other virtual private network (VPN) services [].


Prior to deploying the ransomware, Snatch threat actors were observed spending up to three months on a victim’s system. Within this timeframe, Snatch threat actors exploited the victim’s network [] for the largest possible deployment of ransomware and searching for files and folders [] followed by file encryption [] and run an executable as a file named safe.exe or some variation thereof. In recent victims, the ransomware executable’s name consisted of a string of hexadecimal characters which match the SHA-256 hash of the file in an effort to defeat rule-based detection [][], finds processes []. In some instances, the program attempts to remove all the volume shadow copies from a system [].


The Snatch ransomware executable appends a series of hexadecimal characters to each file and folder name it encrypts—unique to each infection—and leaves behind a text file titled HOW TO RESTORE YOUR FILES.TXT in each folder. Snatch threat actors communicate with their victims through email and the Tox communication platform based on identifiers left in ransom notes or through their extortion blog. Since November 2021, some victims reported receiving a spoofed call from an unknown female who claimed association with Snatch and directed them to the group’s extortion site. In some instances, Snatch victims had a different ransomware variant deployed on their systems, but received a ransom note from Snatch threat actors. As a result, the victims’ data is posted on the ransomware blog involving the different ransomware variant and on the Snatch threat actors’ extortion blog.


Indicators of Compromise (IOCs)


The Snatch IOCs detailed in this section were obtained through FBI investigations from September 2022 through June 2023.


Email Domains and Addresses


Since 2019, Snatch threat actors have used numerous email addresses to email victims. Email addresses used by Snatch threat actors are random but usually originate from one of the following domains listed in Tables 1 and 2:







Table 1: Malicious Email Domains Observed in Use by Snatch Threat Actors

Email Domains



sezname[.]cz



cock[.]li



airmail[.]cc


Table 2 shows a list of legitimate email domains offering encrypted email services that have been used by Snatch threat actors. These email domains are all publicly available and legal. The use of these email domains by a threat actor should not be attributed to the email domains, absent specific articulable facts tending to show they are used at the direction or under the control of a threat actor.









Table 2: Legitimate Email Domains Observed in Use by Snatch Threat Actors

Email Domains



tutanota[.]com / tutamail[.]com / tuta[.]io



mail[.]fr



keemail[.]me



protonmail[.]com / proton[.]me



swisscows[.]email


The email addresses listed in Table 3 were reported by recent victims.






Table 3: Snatch’s Email Addresses Reported by Recent Victims

Email Addresses





Snatch threat actors may gather information about the victim's networks that can be used during targeting.















Table 5: Snatch Threat Actors ATT&CK Techniques for Enterprise – Resource Development

Technique Title



ID



Use



Acquire Infrastructure: Virtual Private Server





Snatch threat actors use compromised user credentials from criminal forums/marketplaces to gain access and maintain persistence on a victim’s network.



External Remote Services





Snatch threat actors may use batch files (.bat) during ransomware execution and data discovery.



System Services: Service Execution





Snatch threat actors compromise domain accounts to maintain persistence on a victim’s network.















Table 9: Snatch Threat Actors ATT&CK Techniques for Enterprise – Defense Evasion

Technique Title



ID



Use



Masquerading





Snatch threat actors delete batch files from a victim’s filesystem once execution is complete.



Modify Registry





Snatch threat actors have attempted to disable a system’s antivirus program to enable persistence and ransomware execution.



Impair Defenses: Safe Mode Boot





Snatch threat actors use brute force to obtain administrator credentials for a victim’s network.









Table 11: Snatch Threat Actors ATT&CK Techniques for Enterprise – Discovery

Technique Title



ID



Use



Query Registry





Snatch threat actors search for information about running processes on a system.









Table 12: Snatch Threat Actors ATT&CK Techniques for Enterprise – Lateral Movement

Technique Title



ID



Use



Remote Services: Remote Desktop Protocol





Snatch threat actors search systems to find files and folders of interest prior to exfiltration.









Table 14: Snatch Threat Actors ATT&CK Techniques for Enterprise – Command and Control

Technique Title



ID



Use



Application Layer Protocols: Web Protocols





Snatch threat actors use exfiltration techniques to steal data from a victim’s network.









Table 16: Snatch Threat Actors ATT&CK Techniques for Enterprise – Impact

Technique Title



ID



Use



Data Encrypted for Impact





Snatch threat actors delete all volume shadow copies from a victim’s filesystem to inhibit system recovery.


MITIGATIONS




These mitigations apply to all stakeholders. The authoring agencies recommend that software manufactures incorporate secure-by-design and -default principles and tactics into their software development practices for hardening software against ransomware attacks (e.g., to prevent threat actors from using Safe Mode to evade detection and file encryption), thus strengthening the secure posture for their customers.


For more information on secure by design, see CISA’s .


The FBI and CISA recommend organizations implement the mitigations below to improve your organization’s cybersecurity posture on the basis of the Snatch threat actor’s activity. These mitigations align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats, tactics, techniques, and procedures. Visit CISA’s ].

  • Using security software to detect instances of remote access software being loaded only in memory.

  • Requiring authorized remote access solutions to be used only from within your network over approved remote access solutions, such as virtual private networks (VPNs) or virtual desktop interfaces (VDIs).

  • Blocking both inbound and outbound connections on common remote access software ports and protocols at the network perimeter.


  • Implement application controls to manage and control execution of software, including allowlisting remote access programs.
    • Application controls should prevent installation and execution of portable versions of unauthorized remote access and other software. A properly configured application allowlisting solution will block any unlisted application execution. Allowlisting is important because antivirus solutions may fail to detect the execution of malicious portable executables when the files use any combination of compression, encryption, or obfuscation.


  • Strictly limit the use of RDP and other remote desktop services. If RDP is necessary, rigorously apply best practices, for example [.

  • Log RDP login attempts.


  • Disable command-line and scripting activities and permissions [.

  • Audit user accounts with administrative privileges and configure access controls according to the principle of least privilege (PoLP) [].

  • In addition, the authoring authorities of this CSA recommend network defenders apply the following mitigations to limit potential adversarial use of common system and network discovery techniques, and to reduce the impact and risk of compromise by ransomware or data extortion actors:


    • Implement a recovery plan to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, and secure location (i.e., hard drive, storage device, the cloud).

    • Maintain offline backups of data and regularly maintain backup and restoration (daily or weekly at minimum). By instituting this practice, an organization limits the severity of disruption to its business practices [ for developing and managing password policies.
      • Use longer passwords consisting of at least eight characters and no more than 64 characters in length [].

      • Implement multiple failed login attempt account lockouts [].

      • Keep all operating systems, software, and firmware up to date. Timely patching is one of the most efficient and cost-effective steps an organization can take to minimize its exposure to cybersecurity threats. Prioritize patching ].

      • Segment networks to prevent the spread of ransomware. Network segmentation can help prevent the spread of ransomware by controlling traffic flows between—and access to—various subnetworks and by restricting adversary lateral movement [].

      • Install, regularly update, and enable real time detection for antivirus software on all hosts.

      • Disable unused ports and protocols [].

      • Disable hyperlinks in received emails.

      • Ensure all backup data is encrypted, immutable (i.e., ensure backup data cannot be altered or deleted), and covers the entire organization’s data infrastructure [ is a whole-of-government approach that gives one central location for ransomware resources and alerts.

      • Resource to mitigate a ransomware attack: and , a


        DISCLAIMER


        The information in this report is being provided “as is” for informational purposes only. FBI and CISA do not endorse any commercial entity, product, or service, including any subjects of analysis. Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by FBI or CISA.


        VERSION HISTORY


        September 20, 2023: Initial version.

        Vollständiger Original-Bericht
        Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf cisa.gov.
        ↗ Original-Artikel auf cisa.gov lesen
    Wie bewertest du diesen Beitrag?
    1 Klick Feedback
    77 Fachleser & IT-Security Experten haben diesen Report heute geteilt
    Teilen mit Netzwerk & Team:
    Community Threat-Level Barometer
    Live Votum

    Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

    Community-Einschätzung (Live): 48 Stimmen
    🟢 Gering: 45% 🟡 Beobachten: 35% 🔴 Akut: 20%

    Community-Analysen & Experten-Meinungen 0

    Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
    Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
    Community Pulse: Relevanz-Einschätzung
    1 Klick Experten-Votum
    🔴 Akute Relevanz 44%
    🟡 In Evaluierung 23%
    🟢 Keine Auswirkung 19%
    Spannende Innovation 14%
    Verwandte Story-Cluster & Quellen (Vektor-KI)
    Port 8095 Engine
    1 Quelle
    CVE-2026-73570: Zimbra SNMP/logwatch RCE exploited in the wild, malware persists via /dev/shm and zimbra cron
    1 Quelle
    Nouveau Panel Alpha Release | Rust + FLTK
    1 Quelle
    Created a small issue with folders and files and hope there may be a terminal command to help or fix it.
    Ähnliche Beiträge
    🔍 Verwandte News

    Auch interessante Nachrichten #StopRansomware: Snatch Ransomware

    Thematisch verwandte Begriffe: StopRansomware, Snatch, Ransomware

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...