Inactive ransomware operator
← All groupsSnatch
142 victims indexed · first seen 5 years ago · last activity 2 years ago
At a glance
- Status
- inactive
- First seen
- 5 years ago
- Last activity
- 2 years ago
- Onion sites
- 9 known endpoints
- Primary sector
- Business Services · 11 hits
About
References
14 linksExternal sources curated by the MISP threat-intel community.
- t.me/snatch_news
- blog.intel471.com/2020/05/21/a-brief-history-of-ta505/
- github.com/albertzsigovits/malware-notes/blob/master/Snatch.md
- intel471.com/blog/a-brief-history-of-ta505
- news.sophos.com/en-us/2019/12/09/snatch-ransomware-reboots-pcs-into-safe-mode-to-bypass-protection/
- news.sophos.com/en-us/2022/03/17/the-ransomware-threat-intelligence-center/
- thedfirreport.com/2020/06/21/snatch-ransomware/
- ti.qianxin.com/uploads/2020/02/13/cb78386a082f465f259b37dae5df4884.pdf
- twitter.com/VK_Intel/status/1191414501297528832
- bleepingcomputer.com/news/security/snatch-ransomware-reboots-to-windows-safe-mode-to-bypass-av-tools/
- crowdstrike.com/blog/financial-motivation-drives-golang-malware-adoption/
- cyborgsecurity.com/cyborg_labs/hunting-ransomware-inhibiting-system-backup-or-recovery/
- secureworks.com/blog/ransomware-groups-use-tor-based-backdoor-for-persistent-access
- ransomlook.io/group/snatch
Timeline
24 monthsTop countries
Top sectors
MITRE ATT&CK
5 techniques · 4 tacticsTactics
Recent victims
Loading…
Onion infrastructure
9 known- http://dwhyj2.top
- http://filesnatchcloud.top
- http://hl66646wtlp2naoqnhattngigjp5palgqmbwixepcjyq5i534acgqyad.onion
- http://hl66646wtlp2naoqnhattngigjp5palgqmbwixepcjyq5i534acgqyad.onion/index.php
- http://sn76920193ch.top
- http://snatch.press
- http://snatchnews.top
- http://snatchteam.cc
- http://sntech2ch.top
Source
Updated 2 years agoData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
Get alerted the next time Snatch posts a victim.
Add Snatch to your watchlist — Pro pings you within 5 minutes of any new Snatch leak-site post, Telegram callout, or affiliate-rebrand inference.

