SafePay Ransomware Targets 260+ Victims Across Various Countries
ID: 1316d56b-359b-5d69-ae9e-ef9e715e38e6
STIX ID: report--1316d56b-359b-5d69-ae9e-ef9e715e38e6
Feed Name: Cyber Press
**SafePay ransomware** is a sophisticated, closed ransomware group responsible for over 265 victims since September 2024, primarily targeting developed economies (notably the US and Germany) with double-extortion attacks that combine file encryption (.safepay) and data theft published on a dark web leak site; the report describes initial access via credential theft, exposed VPN/RDP, MFA bypass, living-off-the-land execution, persistence via legitimate remote tools and custom malware (e.g., QDoor), large-scale exfiltration, and mapped MITRE ATT&CK techniques and IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
