SafePay ransomware: The fast-rising threat targeting MSPs
ID: f99312f3-3596-5e06-a8aa-d121ed6a2632
STIX ID: report--f99312f3-3596-5e06-a8aa-d121ed6a2632
Feed Name: TRU Security by Acronis
SafePay is an emergent ransomware group that surged in Q1 2025, impacting over 200 victims including MSPs and disrupting a major distributor (Ingram Micro). The Acronis TRU analysis describes a PE32 DLL ransomware (requiring regsvr32/rundll32), LockBit-derived code patterns, RDP/VPN intrusions, credential theft, network share discovery (ShareFinder.ps1), file archiving with WinRAR followed by exfiltration with FileZilla, double-extortion using AES/RSA encryption, persistence, anti-analysis and evasion techniques, and includes a file hash and onion C2 IoC.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
