logo

SnapMC skips ransomware, steals data

ID: dfe22c6c-da3a-5264-ac38-f43a24b18c3b

STIX ID: report--dfe22c6c-da3a-5264-ac38-f43a24b18c3b

Feed Name: Fox-IT blog

Threat Score
70/100

Date Published: 2021-10-11

Date Updated: 2026-04-27

Author: Global Threat Intelligence

...
...

NCC Group observed a rapid data breach extortion campaign by an actor they call SnapMC that leverages public-facing application exploits (notably CVE-2019-18935 and SQL injection) to gain reverse shells, run PowerShell-based collection (Invoke-SQLcmd), archive data with 7zip and exfiltrate using the MinIO client (mc.exe), then extort victims via timed threat emails; the report provides TTP mapping, mitigation guidance, and IoCs including file names, paths and hashes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.