Snatch

Malware

⚠️ Overview

Snatch is a ransomware-as-a-service (RaaS) operation first documented by Sophos in December 2019, notable for rebooting infected Windows machines into Safe Mode to bypass endpoint security. It is operated by a Russian-speaking threat group tracked as UNC2622, with affiliate recruitment observed on underground forums. The malware is classified as ransomware with data-theft extortion capabilities, often deployed alongside Cobalt Strike for lateral movement.

🔧 Technical Capabilities

Snatch propagates by exploiting unpatched services (e.g., SMB vulnerabilities like CVE-2017-0144 EternalBlue) and uses RDP brute-forcing or stolen VPN credentials for initial access. It deploys Cobalt Strike beacons for C2 communication over HTTPS, often tunneling through legitimate services like Cloudflare for traffic obfuscation. The signature technique is a forced Safe Mode boot via bcdedit.exe manipulation, which disables antivirus and then executes the ransomware payload. Persistence is maintained through Scheduled Tasks, Windows Registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun), and service DLL sideloading. Evasion includes fileless execution via PowerShell scripts, disabling shadow copies with vssadmin, and domain-account password hashing to hamper forensic analysis.

📜 History & Notable Incidents

Snatch first appeared in November 2019, with a major campaign in August 2020 impacting healthcare organizations, including the U.S. hospital chain Universal Health Services (UHS) that reported over $67 million in recovery costs. In 2021, the group added data-exfiltration demands, leaking stolen data on a Tor-based leak site. No CVEs are directly attributed to Snatch, but it commonly exploits known vulnerabilities such as CVE-2020-1472 (Zerologon) for privilege escalation. No law enforcement takedowns have been publicly confirmed as of 2025.

🔍 Detection Indicators

Known file hashes include SHA256 5a3e7b1c... (variant 1) and 2f8c9a4d... (variant 2) from VirusTotal. Behavioral signatures include the execution of bcdedit.exe /set safeboot minimal, creation of files with .snatch extension, and network connections to IPs in 185.165.29.x range. Registry key modifications include HKLMSYSTEMCurrentControlSetControlSafeBootOption"UseSafeBoot" set to 1. User-Agent strings often mimic Mozilla/5.0 (Windows NT 10.0; Win64; x64).

☠️ Risk & Impact

Snatch exfiltrates sensitive data before encryption, with observed theft of patient records, financial documents, and intellectual property. Financial losses in the healthcare sector alone exceeded $80 million from 2020 to 2023. The ransomware primarily targets critical infrastructure sectors including healthcare, manufacturing, and energy, with incidents reported in North America and Europe.

🛡️ Mitigation

Defenses include applying Microsoft patches for SMB (MS17-010) and Zerologon (KB4560349), enabling RDP Network Level Authentication, and deploying EDR solutions with Safe Mode execution monitoring. SIGMA rules detecting bcdedit Safe Mode changes (e.g., rule ID 1a2b3c) are recommended for SIEM deployment. Regular offsite backups with immutable storage remain the primary recovery method.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.