logo

SafePay Ransomware Targets 260+ Victims Across Various Countries

ID: 1316d56b-359b-5d69-ae9e-ef9e715e38e6

STIX ID: report--1316d56b-359b-5d69-ae9e-ef9e715e38e6

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2025-08-03

Date Updated: 2026-04-13

Author: Priya

...
...

**SafePay ransomware** is a sophisticated, closed ransomware group responsible for over 265 victims since September 2024, primarily targeting developed economies (notably the US and Germany) with double-extortion attacks that combine file encryption (.safepay) and data theft published on a dark web leak site; the report describes initial access via credential theft, exposed VPN/RDP, MFA bypass, living-off-the-land execution, persistence via legitimate remote tools and custom malware (e.g., QDoor), large-scale exfiltration, and mapped MITRE ATT&CK techniques and IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.