Snatch ransomware group
Threat Actor
The Russian Snatch ransomware group uses the double extortion method; accordingly, the payload is made of ransomware and data stealer components. Threat actors use automated brute-force attacks against vulnerable applications in the target organizations. Also, the Snatch ransomware operators also use their affiliate partners to gain initial access to corporate networks.
Incidents Associated with this Threat
- August 18, 2022: European defense contractor, Hensoldt, allegedly Victim of Snatch Ransomware Attack.
- November 30, 2021: R&D Data Breach at Volvo Cars
Malware Used by this Threat Actor
No malware identified for this threat actor.