SafePay ransomware explained: IOCs, TTPs, and defense strategies
ID: 793dac86-9b0c-57d2-9cd7-dc3dfb4fa0b6
STIX ID: report--793dac86-9b0c-57d2-9cd7-dc3dfb4fa0b6
Feed Name: ThreatLocker Blog
SafePay is a prolific ransomware group discovered in November 2024 that has claimed over 200 victims and threatened to release 3.5 TB of Ingram Micro data; the report details their TTPs (exploitation of edge devices, credential theft, use of PowerView ShareFinder.ps1, PSExec/WinRM/RDP for lateral movement), exfiltration tools (WinRAR, 7-Zip, Rclone, FileZilla), shadow copy and backup deletion, double-extortion extortion practices, known SHA-256 hashes and global mutexes, and recommended mitigations using ThreatLocker features.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
