Uptime Hamster: 10d 11h 37mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Snatch

Snatch

0 incidentes 0 paises 0 sectores ransomware AD Ultimo: -
Aliases: Team Truniger, Snatch group, Snatch ransomware, Snatch gang, aunque su operación específica, motivación siguen siendo investigadas
Ver en IntelTracker → APTTrail →
Snatch is a ransomware-as-a-service (RaaS) operation that first emerged in 2018, evolving its tactics consistently since mid-2021 by incorporating successful techniques from other ransomware variants. Assessed with high confidence to be of Russian origin, the group's primary motivation is financial gain through ransomware attacks that involve both data encryption and exfiltration, followed by double extortion. Snatch distinguishes itself by rebooting infected machines into Safe Mode to circumvent security software during the encryption process. The group, originally known as "Team Truniger" after a key member who was a GandCrab affiliate, has also been noted for purchasing previously stolen data from other ransomware gangs to further pressure victims into paying ransoms.

Aliases del actor

Team TrunigerSnatch groupSnatch ransomwareSnatch gangaunque su operación específicamotivación siguen siendo investigadas

Actores similares

aztroteamransomware · 2bonacigroupransomware · 2fsteamransomware · 2malekteamransomware · 2teamxxxransomware · 2thegreenbloodgroupransomware · 2vanirgroupransomware · 2Team Undergroundransomware · 0Silent Ransom Group / LeakedDataransomware · 0ragroupransomware · 0

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Webunknownwww.breachsense.comexecu-search.com - Snatch Data Breach
Webunknowngetbootstrap.comexecu-search.com - Snatch Data Breach
Repositoriounknowngithub.comexecu-search.com - Snatch Data Breach
Repositoriounknowngithub.comexecu-search.com - Snatch Data Breach
Repositoriounknowngithub.comexecu-search.com - Snatch Data Breach
Malware asociado
Smoke Loader, win.simda, Smoke Loader, Gheg, Lumma Stealer, Smoke Loader
Tecnicas MITRE
T1583.005, T1071.004, T1129, TA0005, T1457, T1055
CVEs relacionadas
CVE-2023-4966, CVE-2023-22518
Tipo
ransomware
Pais origen
AD
Motivacion
-
Impacto
119
Actualizado
Sat, 20 Ju

Paises objetivo (SOCRadar)

United Arab EmiratesAfghanistanAustriaAustraliaBrazilCanadaSwitzerlandChinaColombiaCosta Rica

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersReal EstateRental and Leasing ServicesHospitalsAccommodationAir TransportationManufacturing