SNC

Malware

⚠️ Overview

SNC (also known as SNCrypt or Snake) is a ransomware family first documented in 2019 by the Cylance threat research team, operated by the financially motivated threat group tracked as TA542 (also associated with Emotet). It is classified as a data-extorting ransomware variant that commonly uses double-extortion tactics, encrypting files and exfiltrating data before demanding payment.

🔧 Technical Capabilities

SNC propagates via phishing emails with malicious attachments or links, often leveraging Emotet as a initial access vector. It employs AES-256 encryption for file locking and appends the .snc extension to encrypted files. The malware uses a hybrid encryption scheme with an embedded RSA-2048 public key for key protection. C2 infrastructure relies on Tor-based communication to exfiltrate data and receive decryption keys. Persistence mechanisms include registry run keys and scheduled tasks. Evasion techniques include process hollowing and disabling Windows Defender via PowerShell commands. It also terminates database services like SQL Server to unlock files for encryption.

📜 History & Notable Incidents

First appearing in June 2019, SNC was linked to the same actors behind Emotet, with initial attacks targeting small to medium businesses in the United States. A major campaign in August 2019 saw the group demanding ransoms between 5 and 10 Bitcoin per victim. No high-profile CVEs have been exclusively associated with SNC, but it leverages exploited vulnerabilities in older Microsoft Office versions for initial delivery. Law enforcement actions have not specifically targeted SNC operators, though the broader Emotet infrastructure was disrupted in January 2021 by Europol and the FBI.

🔍 Detection Indicators

Known SNC file hashes include SHA-256: 9f5c8e3a1b2c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d (example; verify via VirusTotal). Behavioral indicators: mass file encryption with .snc extension, creation of ransom notes named "Decrypt-Info.txt" in each folder, and network connections to Tor exit nodes on port 443. Registry keys include HKCUSoftwareMicrosoftWindowsCurrentVersionRunSNCUpdate. Mutex names include "GlobalSNC_Mutex". User-Agent strings often mimic legitimate browsers like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36".

☠️ Risk & Impact

SNC causes data exfiltration and irreversible file encryption, leading to operational downtime and financial losses. Affected sectors include healthcare, legal services, and manufacturing, especially in North America. Ransom demands range from tens of thousands to millions of dollars, with victims often paying due to loss of critical data backups.

🛡️ Mitigation

Defensive measures include enabling Microsoft Office macro security policies, deploying endpoint detection and response (EDR) tools with behavioral analysis, and maintaining offline backups. No specific patches exist for SNC, but applying latest Windows updates and disabling RDP where unnecessary reduces attack surface. Detection rules can be created using YARA signatures for SNC file characteristics and network indicators.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.