logo

SafePay ransomware: The fast-rising threat targeting MSPs

ID: f99312f3-3596-5e06-a8aa-d121ed6a2632

STIX ID: report--f99312f3-3596-5e06-a8aa-d121ed6a2632

Feed Name: TRU Security by Acronis

Threat Score
85/100

Date Published: 2025-07-08

Date Updated: 2026-07-24

...
...

SafePay is an emergent ransomware group that surged in Q1 2025, impacting over 200 victims including MSPs and disrupting a major distributor (Ingram Micro). The Acronis TRU analysis describes a PE32 DLL ransomware (requiring regsvr32/rundll32), LockBit-derived code patterns, RDP/VPN intrusions, credential theft, network share discovery (ShareFinder.ps1), file archiving with WinRAR followed by exfiltration with FileZilla, double-extortion using AES/RSA encryption, persistence, anti-analysis and evasion techniques, and includes a file hash and onion C2 IoC.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.