Snatch ransomware group
The Russian Snatch ransomware group uses the double extortion method; accordingly, the payload is made of ransomware and data stealer components. Threat actors use automated brute-force attacks against vulnerable applications in the target organizations. Also, the Snatch ransomware operators also use their affiliate partners to gain initial access to corporate networks.
Incidents Associated with this Threat
- August 18, 2022: European defense contractor, Hensoldt, allegedly Victim of Snatch Ransomware Attack.
- November 30, 2021: R&D Data Breach at Volvo Cars