THREAT ACTOR: Snatch ransomware group
The Russian Snatch ransomware group uses the double extortion method; accordingly, the payload is made of ransomware and data stealer components. Threat actors use automated brute-force attacks against vulnerable applications in the target organizations. Also, the Snatch ransomware operators also use their affiliate partners to gain initial access to corporate networks.
Incidents Associated with this Threat
- R&D Data Breach at Volvo Cars November 30, 2021:
Malware Used by this Threat Actor
No malware identified for this threat actor.