According to a new discovery, the creators of Snatch ransomware are using a brand new trick to bypass software antivirus files victims'. This trick allows them to avoid detection.
How do hackers achieve this? They restart the infected computer in Safe Mode and start the file encryption process from there.
Restarting in Safe Mode is important for hackers, because most antivirus software does not run in this mode of Windows.
The hackers behind Snatch managed to run their ransomware in Safe Mode and evade detection.
The hackers' trick was discovered by researchers at Sophos Labs. The research team said that this is a clever trick, which can become very dangerous, as it can be adopted by other ransomware gangs. For this reason, Sophos Labs decided to make its discovery public to draw the attention of all security.
Snatch ransomware
The hackers behind Snatch began their activities in the summer of 2018. Although they have carried out some attacks, using various other tricks, there is not much information about their ransomware.
This lack of information is due to the fact that Snatch does not target home users nor does it use mass distribution methods (e.g. spam emails or exploit kits), which usually attract the attention of security companies.
Snatch ransomware targets are usually carefully selected targets, such as companies and public or government organizations.
This type of targeting and methodology is known as “big game hunting” and is used by several ransomware gangs.
The idea behind this is to target large companies and organizations, from where hackers can secure hundreds of thousands of dollars in ransom with a single attack.
The most well-known ransomware that operates in this way are Ryuk, SamSam, Matrix, BitPaymer, and LockerGoga.

hackers " recruit hackers through hacking forums
Sophos researchers discovered that the hacking group is placing advertisements on hacking forums and soliciting collaborators for its activities.
According to the ad, the group was “looking for partners with access to RDP\VNC\TeamViewer\WebShell\SQL inj [SQL injection] in corporate networks, stores and other companies.”
The Snatch team "buys" access to a compromised network, or collaborates with other hackers to compromise a company.
Once hackers gain access to a company's network, they are in no hurry to encrypt files. They can remain on the network for days or even weeks.
slowly escalate access to internal domain and spread to as many computers on an internal network as possible.
To accomplish this, hackers use legitimate tools and penetration testing toolkits, such as Cobalt Strike, Advanced Scanner Port, Process Hacker, IObit Uninstaller, PowerTool, and PsExec. These are common tools. Therefore, most antivirus products are not triggered by them.
They then restart the affected computers in Safe Mode and begin the file encryption process.
Data theft
Sophos discovered that the hackers behind Snatch don't just encrypt files, as all ransomware does. The hacking group often steals data.
This makes the group extremely dangerous, because victims may pay the ransom, but the data is still in the hands of the attackers and can be leaked online or sold.
This type of behavior is very unusual and may make Snatch one of the most dangerous ransomware.
However, this type of attack takes a lot of time, which is why the number of Snatch victims is very small (so far).
Coverware, a company that specializes in negotiations between ransomware victims and attackers, said it handled 12 cases between July and October 2019 related to Snatch ransomware. The payments ranged from $2,000 to $35,000.
Sophos recommends that companies secure ports and services exposed to the internet to stay safe.
