Emerging Threat Actor: SafePay Ransomware
ID: adcf611b-8e83-54d7-b96f-7507bef6c17b
STIX ID: report--adcf611b-8e83-54d7-b96f-7507bef6c17b
Feed Name: Halcyon Blog
SafePay is a rapidly rising Ransomware-as-a-Service (RaaS) group active since November 2024 that employs double extortion—encrypting systems (appending ".safepay") and exfiltrating data to public leak sites on Tor and The Open Network (TON). The group shows technical maturity and operational discipline, reuses elements from leaked LockBit code, leverages known enterprise vulnerabilities and legitimate remote management tools for access and persistence, uses credential-stealing tools like Mimikatz during post-exploitation, and permits affiliates to conduct attacks under its name, targeting mid-to-large organizations across multiple industries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
