What is Snatch Ransomware and How to Remove It 1

What is Snatch Ransomware and How to Remove It

It seems that crimeware developers never sleep as defenses rise. They are always looking for different ways to improve their offensive weapons. One of the newest techniques is a form of ransomware that can force a Windows device to reboot into Safe Mode just before encryption begins, in order to bypass endpoint protection.

This particular breed is known as Snatch because of its authors who refer to themselves as the Snatch Team. It was discovered by Sophos Labs researchers, who summarized their discovery, along with information on how such gangs got into hit-list businesses and other assets.

We will explain what Snatch ransomware is, how it works, and how you can remove it from your devices.

What is Snatch Ransomware?

Snatch is a new variant of ransomware whose executable forces Windows devices to reboot into Safe Mode before the encryption process begins, in order to bypass endpoint protection that usually doesn’t work in this mode.

Discovered by SophosLabs researchers and the Sophos Managed Threat Response team, the grabber ransomware is among multiple malware constellation components used in a series of carefully orchestrated attacks with extensive data collection.

How to Remove Snatch Ransomware Attack

The new strain of ransomware uses a unique infection method that applies advanced AES encryption so that users whose machines are infected cannot access their files.

The Snatch ransomware was first noticeably active in April 2019, but was released at the end of 2018. However, the spike in encrypted files and ransom notes led to it being discovered and tracked by the team of researchers at Sophos.

The crypto-virus form attacks high-profile targets, but this new strain, created using the Google Go program, consists of a number of tools, including a data thief and a ransomware feature. It also has a Cobalt Strike reverse shell and other tools used by penetration testers and system administrators.

Note:

How Does Snatch Ransomware Work?

As a file-locking virus, Snatch ransomware has no affiliation with other types. Still, its developers have released nine variants of the threat that add different extensions after the data is encrypted with the AES cipher.

The trick is to restart the machines in Safe Mode and then the ransomware will encrypt your files, restricting access to your data. After that, hackers try to extort money from you by demanding ransom in the form of Bitcoin in exchange for unlocking your files and restoring data access.

How to Remove Snatch Ransomware Works

There’s a reason their tricks work. Some antivirus software won’t start in Safe Mode, and the developers have discovered that they can easily change a Windows registry key and start your machine in Safe Mode. So the ransomware runs undetected by your security software.

When first installed on your device, it comes via SuperBackupMan, a Windows service, and installs just before your computer starts rebooting so you can’t stop it in time.

How to Remove Snatch Ransomware Superbackupman

Once installed, attackers use administrative access to run BCDEDIT, a Windows command line tool, to force your computer to restart in Safe Mode immediately.

It then creates a randomly named executable in your %AppData% or %LocalAppData% folder, which launches and starts scanning your computer’s drive letters for files to be encrypted.

Files Targeted by Snatch Ransomware

There are certain file extensions it encrypts, including .doc, .docx, .pdf, .xls, and others; this will break the extensions and change them to Snatch so you can’t turn them back on.

The ransomware leaves a Readme_Restore_Files.txt text file note and demands anything between one and five Bitcoins in exchange for a decryption key, with information on how to contact hackers to get your data files back.

How to Remove Snatch Ransomware Message

After the ransomware has completely scanned your computer, it uses a Windows command, vssadmin.exe, to delete all Shadow Volume Copies on it, so you can’t recover them and use them to restore encrypted data files. The final step is to encrypt all the data files on your hard drive.

Currently, infected files cannot be decrypted due to the complex nature of AES encryption used. However, if your computer is infected by restoring your files from the latest backup, you still have a lifeline.

How to Remove Snatch Ransomware File Hostage

Snatch ransomware targets regular users via spam emails. But today, the main target is companies. By paying such criminals, not only do you lose money and you have no guarantee that they will send you the decryption key, but it also encourages them to continue their cybercrime.

If you don’t have an updated backup, there’s not much you can do other than wait for the security experts to come up with a Snatch ransomware decryptor. This may take a long time, but there are other ways to protect yourself from such attacks.

How to Remove Snatch Ransomware from Your Computer

One of the best ways to remove Snatch ransomware and other malware is to install good antivirus security software like Malwarebytes or SpyHunter that can scan, detect and remove the threat. Because it’s a completely new malware, not all antivirus engines can catch it, so it’s good to scan using a few programs.

You can protect yourself and your devices from ransomware attacks by taking simple steps such as downloading software from trusted sources and avoiding opening email attachments from untrusted sources.

Removing Snatch Ransomware File Types

Other ways to protect yourself and your organization from Snatch and other types of ransomware include:

  • Maintain an up-to-date operating system and keep backing up your data.
  • Perform a regular password check.
  • Deploy multi-layered, comprehensive security software to protect all entry points from a ransomware attack.
  • Snatch attackers secure remote access tools and other vulnerable programs as they recruit other criminals who have experience using Web shells or can break into SQL servers through injection attacks.
  • Protect your Remote Desktop interface by putting it behind a VPN on your network so people can’t access them without VPN credentials.
  • While Snatch uses such access points and abutments to gain entry, conduct regular and thorough checks of all devices in your home or organization to ensure they are protected and monitored.
  • Set up and use multi-factor authentication for all administrators in your organization so that attackers don’t force your credentials.
  • Conduct a full threat hunt on your network to identify such activities before infection.

Protect Your System

Snatch ransomware can be almost life-threatening in how it works to paralyze your files and devices. Before you even consider paying this ransom, try the steps above to remove the threat and always take preventive measures to ensure that this and such threats do not appear on your computer or network.

Next: If you suspect your phone is infected with ransomware, see our next article to learn how to detect and remove it.

Support our work ❤️

If you enjoyed this article, consider leaving a tip to help us keep publishing great content.

Secure payment on PayPal
Moyens I/O Staff is a team of expert writers passionate about technology, innovation, and digital trends. With strong expertise in AI, mobile apps, gaming, and digital culture, we produce accurate, verified, and valuable content. Our mission: to provide reliable and clear information to help you navigate the ever-evolving digital world. Discover what our readers say on Trustpilot.