logo

Emerging Threat Actor: SafePay Ransomware

ID: adcf611b-8e83-54d7-b96f-7507bef6c17b

STIX ID: report--adcf611b-8e83-54d7-b96f-7507bef6c17b

Feed Name: Halcyon Blog

Threat Score
78/100

Date Published: 2025-07-07

Date Updated: 2026-04-28

...
...

SafePay is a rapidly rising Ransomware-as-a-Service (RaaS) group active since November 2024 that employs double extortion—encrypting systems (appending ".safepay") and exfiltrating data to public leak sites on Tor and The Open Network (TON). The group shows technical maturity and operational discipline, reuses elements from leaked LockBit code, leverages known enterprise vulnerabilities and legitimate remote management tools for access and persistence, uses credential-stealing tools like Mimikatz during post-exploitation, and permits affiliates to conduct attacks under its name, targeting mid-to-large organizations across multiple industries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.