logo

SafePay ransomware: The fast-rising threat targeting MSPs

ID: e5360380-5ace-5042-8584-55936417d208

STIX ID: report--e5360380-5ace-5042-8584-55936417d208

Feed Name: TRU Security by Acronis

Threat Score
88/100

Date Published: 2025-07-08

Date Updated: 2026-07-24

...
...

SafePay is a rapidly emerging ransomware group active since 2024 that has grown to over 200 victims by Q1 2025 and is linked to a disruptive attack on distributor Ingram Micro; Acronis TRU analyzed a PE32 DLL SafePay sample that requires a password to run, decrypts all strings at runtime, resolves imports dynamically, abuses CMSTPLUA for privilege escalation, disables protections, deletes shadow copies and logs, exfiltrates data via compressed archives and FileZilla, and encrypts files using AES keys protected with RSA, appending '.safepay' while supporting arguments for propagation, network encryption and stealth, with a listed file hash and a Tor C2 URL provided as IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.