HackerFeeds
All ransomware groups

safepay

503 tracked victims
·first seen 2023-11-10·last activity 2026-06-22

Group profile

SafePay emerged in September 2024 as a rapidly growing ransomware operation that explicitly disavows the RaaS model and manages all operations internally, claiming over 300 victims worldwide by mid-2025 with a high-profile early attack against UK telematics firm Microlise stealing 1.2 TB of data.

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1078Valid Accounts

    The threat actor accessed the endpoint via Remote Desktop Protocol (RDP) using valid credentials.

  • T1091Replication Through Removable Media

  • T1189Drive-by Compromise

  • T1190Exploit Public-Facing Application

  • T1566.001Phishing: Spearphishing Attachment

  • T1566.002Phishing: Spearphishing Link

  • T1566.003Phishing: Spearphishing Voice

TA0002

Execution

  • T1047Windows Management Instrumentation

    Employed WMI commands to execute processes on remote systems.

  • T1053.005Scheduled Task/Job: Scheduled Task

  • T1059Command and Scripting Interpreter

    Utilized PowerShell scripts, such as ShareFinder.ps1, to execute commands on the compromised system.

  • T1059.001Command and Scripting Interpreter: PowerShell

  • T1059.003Command and Scripting Interpreter: Windows Command Shell

  • T1059.005Command and Scripting Interpreter: Visual Basic

  • T1106Native API

  • T1129Shared Modules

  • T1203Exploitation for Client Execution

  • T1204.001User Execution: Malicious Link

  • T1204.002User Execution: Malicious File

TA0003

Persistence

  • T1078Valid Accounts

    Maintained access through the use of compromised valid accounts.

  • T1098Account Manipulation

  • T1505.004Server Software Component: IIS Components

  • T1542.003Pre-OS Boot: Bootkit

  • T1543.003Create or Modify System Process: Windows Service

  • T1547Boot or Logon Autostart Execution

  • T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

  • T1547.009Boot or Logon Autostart Execution: Shortcut Modification

  • T1574.001Hijack Execution Flow: DLL Search Order Hijacking

TA0004

Privilege Escalation

  • T1078Valid Accounts

    Escalated privileges by leveraging valid domain accounts.

  • T1134.002Access Token Manipulation: Create Process with Token

  • T1134.004Access Token Manipulation: Parent PID Spoofing

TA0005

Defense Evasion

  • T1014Rootkit

  • T1027Obfuscated Files or Information

  • T1027.002Obfuscated Files or Information: Software Packing

  • T1027.005Obfuscated Files or Information: Indicator Removal from Tools

  • T1027.007Obfuscated Files or Information: Dynamic API Resolution

  • T1027.009Obfuscated Files or Information: Embedded Payloads

  • T1027.013Obfuscated Files or Information: Encrypted/Encoded File

  • T1027.016Obfuscated Files or Information: Junk Code Insertion

  • T1036Masquerading

  • T1036.003Masquerading: Rename Legitimate Utilities

  • T1036.004Masquerading: Masquerade Task or Service

  • T1036.005Masquerading: Match Legitimate Name or Location

  • T1036.007Masquerading: Double File Extension

  • T1036.008Masquerading: Masquerade File Type

  • T1055Process Injection

  • T1055.001Process Injection: DLL Injection

  • T1070Indicator Removal

  • T1070.003Indicator Removal: Clear Command History

  • T1070.004Indicator Removal: File Deletion

  • T1070.006Indicator Removal: Timestomp

  • T1112Modify Registry

  • T1140Deobfuscate/Decode Files or Information

  • T1218System Binary Proxy Execution

  • T1218.004System Binary Proxy Execution: InstallUtil

  • T1218.005System Binary Proxy Execution: Mshta

  • T1218.007System Binary Proxy Execution: Msiexec

  • T1218.010System Binary Proxy Execution: Regsvr32

  • T1218.011System Binary Proxy Execution: Rundll32

  • T1218.014System Binary Proxy Execution: MMC

  • T1220XSL Script Processing

  • T1221Template Injection

  • T1222File and Directory Permissions Modification

  • T1497Virtualization/Sandbox Evasion

  • T1497.001Virtualization/Sandbox Evasion: System Checks

  • T1497.003Virtualization/Sandbox Evasion: Time Based Checks

  • T1553.002Subvert Trust Controls: Code Signing

  • T1562.001Impair Defenses: Disable or Modify Tools

  • T1562.004Impair Defenses: Disable or Modify System Firewall

  • T1564.001Hidden Artifacts: Hidden Files and Directories

  • T1574Hijack Execution Flow

  • T1574.013Hijack Execution Flow: KernelCallbackTable

  • T1620Reflective DLL Injection

  • T1622Debugger Evasion

TA0006

Credential Access

  • T1003OS Credential Dumping

    Employed tools like lsassy.py to dump credentials from the operating system.

  • T1003.003OS Credential Dumping: NTDS

  • T1056Input Capture

  • T1056.001Input Capture: Keylogging

  • T1110.003Brute Force: Password Spraying

  • T1555Credentials from Password Stores

  • T1557.001Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning

TA0007

Discovery

  • T1010Application Window Discovery

  • T1012Query Registry

  • T1016System Network Configuration Discovery

  • T1033System Owner/User Discovery

  • T1046Network Service Discovery

  • T1049System Network Connections Discovery

  • T1057Process Discovery

  • T1082System Information Discovery

  • T1083File and Directory Discovery

  • T1087.002Account Discovery: Domain Account

  • T1119Automated Collection

  • T1120Peripheral Device Discovery

  • T1124Time Discovery

  • T1482Domain Trust Discovery

    Conducted domain trust discovery using commands like 'net group domain admins /domain' and 'nltest.exe'.

  • T1614.001System Location Discovery: System Language Discovery

TA0008

Lateral Movement

  • T1021Remote Services

    Moved laterally within the network using Remote Desktop Protocol (RDP) and Windows Management Instrumentation (WMI).

  • T1021.001Remote Services: Remote Desktop Protocol

  • T1021.002Remote Services: SMB/Windows Admin Shares

  • T1021.004Remote Services: SSH

  • T1091Replication Through Removable Media

  • T1534Internal Spearphishing

TA0009

Collection

  • T1005Data from Local System

  • T1074Data Staged

  • T1074.001Data Staged: Local Data Staging

  • T1560Archive Collected Data

    Archived files using WinRAR with specific command-line options to prepare data for exfiltration.

  • T1560.002Archive Collected Data: Archive via Library

  • T1560.003Archive Collected Data: Archive via Custom Method

TA0010

Exfiltration

  • T1041Exfiltration Over C2 Channel

  • T1048.003Exfiltration Over Alternative Protocol: Unencrypted Non-C2 Protocol

  • T1052.001Exfiltration Over Physical Medium: Exfiltration over USB

  • T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage

TA0011

Command and Control

TA0040

Impact

  • T1485Data Destruction

  • T1486Data Encrypted for Impact

    Encrypted files and appended the '.safepay' extension, leaving a ransom note named 'readme_safepay.txt'.

  • T1489Service Stop

  • T1490Inhibit System Recovery

    Deleted volume shadow copies to inhibit system recovery.

  • T1491.001Defacement: Internal Defacement

  • T1529System Shutdown/Reboot

  • T1561.001Disk Wipe: Disk Content Wipe

  • T1561.002Disk Wipe: Disk Structure Wipe

TA0042

Resource Development

TA0043

Reconnaissance

  • T1589.002Gather Victim Identity Information: Email Addresses

  • T1591Gather Victim Org Information

  • T1591.004Gather Victim Org Information: Identify Roles

  • T1593.001Search Open Websites/Domains: Social Media

Recent victims

showing 50 of 503
DateWebsite / victimSectorCountry
2026-06-22
ehg.bayern
ehg.bayernehg.bayern
Not FoundDE
2026-06-17
seinordovest.it
seinordovest.itseinordovest.it
Not FoundIT
2026-06-17
harcourts.net
harcourts.netharcourts.net
Consumer ServicesAU
2026-06-17
zaunsysteme.de
zaunsysteme.dezaunsysteme.de
ManufacturingDE
2026-06-17
brscappuccio.it
brscappuccio.itbrscappuccio.it
Consumer ServicesIT
2026-06-17
gut-heckenhof.de
gut-heckenhof.degut-heckenhof.de
Agriculture and Food ProductionDE
2026-05-05
hughstirling.co.uk
hughstirling.co.ukhughstirling.co.uk
Business ServicesDE
2026-06-15
tokyocivil.co.jp
tokyocivil.co.jptokyocivil.co.jp
ConstructionJP
2026-06-15
kawaius.com
kawaius.comkawaius.com
Not FoundUS
2026-06-15
musenet.co.jp
musenet.co.jpmusenet.co.jp
TechnologyJP
2026-06-15
bautz-maschinenbau.de
bautz-maschinenbau.debautz-maschinenbau.de
ManufacturingDE
2026-06-15
aquaclean.com
aquaclean.comaquaclean.com
Consumer ServicesES
2026-06-15
hoodriversheriff.com
hoodriversheriff.comhoodriversheriff.com
Public SectorUS
2026-05-21
iql-nog.com
iql-nog.comiql-nog.com
Not FoundES
2026-06-01
tavolaspa.com
tavolaspa.comtavolaspa.com
Hospitality and TourismIT
2026-06-01
parsa-beauty.de
parsa-beauty.deparsa-beauty.de
Consumer ServicesDE
2026-06-01
soraris.it
soraris.itsoraris.it
TechnologyIT
2026-06-01
lcnet.eu
lcnet.eulcnet.eu
TechnologyDE
2026-06-01
verzolla.com
verzolla.comverzolla.com
Not FoundIT
2026-06-01
compactmould.com
compactmould.comcompactmould.com
ManufacturingCA
2026-05-25
eitecpro.co.jp
eitecpro.co.jpeitecpro.co.jp
TechnologyJP
2026-05-25
tme-rusta.de
tme-rusta.detme-rusta.de
Business ServicesDE
2026-05-25
cyuou.com
cyuou.comcyuou.com
Not FoundJP
2026-04-29
vdmtrucking.com
vdmtrucking.comvdmtrucking.com
Transportation/LogisticsCA
2026-05-19
olipes.com
olipes.comolipes.com
Not FoundES
2026-04-25
harrisoncountywv.com
harrisoncountywv.comharrisoncountywv.com
Public SectorUS
2026-03-08
printroom.co.uk
printroom.co.ukprintroom.co.uk
Business ServicesGB
2026-05-18
hautarzt-budihardja.de
hautarzt-budihardja.dehautarzt-budihardja.de
HealthcareDE
2026-05-18
mediafrance.de
mediafrance.demediafrance.de
Consumer ServicesDE
2026-05-18
ashleytimber.co.uk
ashleytimber.co.ukashleytimber.co.uk
ConstructionGB
2026-05-18
adlan.com
adlan.comadlan.com
Not FoundCA
2026-05-18
berlinmobil.de
Berlinmobil.deBerlinmobil.de
Transportation/LogisticsDE
2026-05-06
smp.cat
smp.catsmp.cat
Not FoundES
2026-05-06
gingerichtrucking.com
gingerichtrucking.comgingerichtrucking.com
Transportation/LogisticsUS
2026-05-06
jmige.com
jmige.comjmige.com
Not FoundUS
2026-04-02
id-s.de
id-s.deid-s.de
TechnologyDE
2026-05-06
mbk-gmbh.de
mbk-gmbh.dembk-gmbh.de
Business ServicesDE
2026-05-06
ettp.be
ettp.beettp.be
Not FoundBE
2026-05-06
studioubertazzi.it
studioubertazzi.itstudioubertazzi.it
Consumer ServicesIT
2026-05-06
globalmerchservices.com
globalmerchservices.comglobalmerchservices.com
Business ServicesGB
2026-05-06
soavegel.it
soavegel.itsoavegel.it
Agriculture and Food ProductionIT
2026-05-04
hokuyo2006.co.jp
hokuyo2006.co.jphokuyo2006.co.jp
ManufacturingJP
2026-03-07
bootstransport.ca
bootstransport.cabootstransport.ca
Transportation/LogisticsCA
2026-05-04
dahlgrenscement.se
dahlgrenscement.sedahlgrenscement.se
ManufacturingSE
2026-05-04
maiadouro.pt
maiadouro.ptmaiadouro.pt
Agriculture and Food ProductionPT
2026-05-04
zonaovest.to.it
zonaovest.to.itzonaovest.to.it
Not FoundIT
2026-05-04
fital-treppenlifte.de
fital-treppenlifte.defital-treppenlifte.de
Consumer ServicesDE
2026-04-13
energyaction.com.au
energyaction.com.auenergyaction.com.au
EnergyAU
2026-04-26
hpk.hamburg
hpk.hamburghpk.hamburg
Not FoundDE
2026-04-17
bbalawgroup.com
bbalawgroup.combbalawgroup.com
Business ServicesUS