Skip to main content

Operator dossier

Snatch is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 142 public victims claimed by this operator between November 29, 2021 and May 16, 2024. Snatch is a ransomware group that emerged in November 2021, operating with primarily financial motivations and targeting organizations across multiple sectors including business services, government, education, manufacturing, and healthcare. The group has compromised at least 142 known victims, with their attacks concentrated primarily in the United States, United Kingdom, Canada, India, and France. Little is publicly documented about Snatch's specific country of origin or affiliations with other cybercriminal organizations, though their operational patterns suggest they function as an independent ransomware operation. The group's attack methodology and specific technical details regarding initial access vectors, encryption methods, and data exfiltration practices have not been extensively documented in public threat intelligence reports from major security firms or government agencies. While Snatch has maintained a notable victim count across diverse geographic regions and industry sectors, there are no widely reported major campaigns or high-profile attacks that have drawn significant public attention or law enforcement action. Based on available public information, Snatch appears to remain an active ransomware operation as of recent reporting periods, though comprehensive details about their current operational status and recent activities are limited in open-source intelligence.

Most-targeted sectors

Most-affected countries

Recent disclosures by Snatch

Most recent 30 of 142 indexed disclosures. Click any row for the full per-victim dossier.

See every disclosure indexed for Snatch

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Inactive ransomware operator

All groups

Snatch

142 victims indexed · first seen 5 years ago · last activity 2 years ago

142
Victims indexed
#61 of 356 tracked operators
2y 6m
Active period
Nov 2021 → May 2024
10
Countries hit
top United States · 29

At a glance

Status
inactive
First seen
5 years ago
Last activity
2 years ago
Onion sites
9 known endpoints
Primary sector
Business Services · 11 hits

About

Snatch is a ransomware group that emerged in November 2021, operating with primarily financial motivations and targeting organizations across multiple sectors including business services, government, education, manufacturing, and healthcare. The group has compromised at least 142 known victims, with their attacks concentrated primarily in the United States, United Kingdom, Canada, India, and France. Little is publicly documented about Snatch's specific country of origin or affiliations with other cybercriminal organizations, though their operational patterns suggest they function as an independent ransomware operation. The group's attack methodology and specific technical details regarding initial access vectors, encryption methods, and data exfiltration practices have not been extensively documented in public threat intelligence reports from major security firms or government agencies. While Snatch has maintained a notable victim count across diverse geographic regions and industry sectors, there are no widely reported major campaigns or high-profile attacks that have drawn significant public attention or law enforcement action. Based on available public information, Snatch appears to remain an active ransomware operation as of recent reporting periods, though comprehensive details about their current operational status and recent activities are limited in open-source intelligence.

References

14 links

External sources curated by the MISP threat-intel community.

Timeline

24 months
2022-03-01T00:00:00+00:00 · 42022-05-01T00:00:00+00:00 · 12022-06-01T00:00:00+00:00 · 22022-08-01T00:00:00+00:00 · 12022-10-01T00:00:00+00:00 · 72022-11-01T00:00:00+00:00 · 62022-12-01T00:00:00+00:00 · 62023-01-01T00:00:00+00:00 · 12023-02-01T00:00:00+00:00 · 22023-03-01T00:00:00+00:00 · 22023-04-01T00:00:00+00:00 · 22023-05-01T00:00:00+00:00 · 92023-06-01T00:00:00+00:00 · 152023-07-01T00:00:00+00:00 · 52023-08-01T00:00:00+00:00 · 32023-09-01T00:00:00+00:00 · 42023-10-01T00:00:00+00:00 · 52023-11-01T00:00:00+00:00 · 92023-12-01T00:00:00+00:00 · 32024-01-01T00:00:00+00:00 · 52024-02-01T00:00:00+00:00 · 32024-03-01T00:00:00+00:00 · 52024-04-01T00:00:00+00:00 · 12024-05-01T00:00:00+00:00 · 2
2022-03-01T00:00:00+00:002024-05-01T00:00:00+00:00

Top countries

🇺🇸 United States
29
🇬🇧 United Kingdom
6
🇨🇦 Canada
5
🇮🇳 India
4
🇫🇷 France
3
🇦🇪 UAE
3
🇩🇪 Germany
2
🇿🇦 South Africa
2

Top sectors

Business Services
11
Government
8
Education
8
Manufacturing
7
Healthcare
7
Financial
6
Engineering
3
Healthcare Services
3

MITRE ATT&CK

5 techniques · 4 tactics

Tactics

Initial AccessExecutionDefense EvasionImpact

Techniques

  • T1566Phishing
  • T1059Command and Scripting Interpreter
  • T1027Obfuscated Files or Information
  • T1562Impair Defenses
  • T1486Data Encrypted for Impact

Recent victims

Loading…

Onion infrastructure

9 known
  • http://dwhyj2.top
  • http://filesnatchcloud.top
  • http://hl66646wtlp2naoqnhattngigjp5palgqmbwixepcjyq5i534acgqyad.onion
  • http://hl66646wtlp2naoqnhattngigjp5palgqmbwixepcjyq5i534acgqyad.onion/index.php
  • http://sn76920193ch.top
  • http://snatch.press
  • http://snatchnews.top
  • http://snatchteam.cc
  • http://sntech2ch.top

Source

Updated 2 years ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time Snatch posts a victim.

Add Snatch to your watchlist — Pro pings you within 5 minutes of any new Snatch leak-site post, Telegram callout, or affiliate-rebrand inference.