Experts spotted a new piece of the Snatch ransomware that reboots computers it infects into Safe Mode to bypass resident security solutions. The malware attempts to exploit the fact that many security tools are automatically disabled when Windows machines run in Safe Mode. The members of the gang has been observed recruiting hackers on hacking forums. Snatch malware runs on almost any versions of Windows, from 7 through 10, for both 32- and 64-bit versions. The attackers used the same collection of tools in other opportunistic attacks against organizations worldwide, including the United States, Canada and several European countries.”]
Source: https://securityaffairs.co/wordpress/94902/malware/snatch-ransomware-disables-av.html

