logo

SafePay Ransomware Infected 260+ Victims Across Multiple Countries

ID: 31219c98-4f02-5be0-8c91-f51c6cd74df7

STIX ID: report--31219c98-4f02-5be0-8c91-f51c6cd74df7

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-08-02

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

SafePay is a centralized and increasingly aggressive ransomware group active since September 2024 that has claimed 265 confirmed attacks worldwide, primarily targeting developed economies (notably the United States and Germany) and sectors such as manufacturing, technology, education, and business services. The report describes a sophisticated double-extortion model with a public data leak site, persistent remote access using legitimate tools (ConnectWise ScreenConnect), disabling of Microsoft Defender and other security controls, encrypted strings and packing to evade detection, registry/startup persistence, and a custom QDoor backdoor; it also notes an embedded language check to avoid systems configured for certain CIS-region languages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.