logo

It’s Not Safe To Pay SafePay | Huntress

ID: f8fc88b7-9d93-5cdd-abb6-467caa7981bd

STIX ID: report--f8fc88b7-9d93-5cdd-abb6-467caa7981bd

Feed Name: Huntress Blog

Threat Score
78/100

Date Published: 2024-11-14

Date Updated: 2026-04-28

...
...

SafePay ransomware: Huntress observed two separate intrusions where a SafePay ransomware variant encrypted files (using the .safepay extension and readme_safepay.txt notes) and published victims on a Tor/TON leak site. Attackers used valid RDP credentials from internal VPN-assigned workstations, ran ShareFinder.ps1 for network share discovery, archived data with WinRAR (and installed FileZilla), and deployed encryption via regsvr32 executing a malicious DLL; the binary shows strong overlap with leaked LockBit code, includes Cyrillic-language checks, string obfuscation, process/service termination routines, UAC bypass behavior, and shadow-copy deletion; Huntress provides detection guidance, Sigma rules, and MITRE ATT&CK mappings, and observed 22 victims listed on the leak site.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.