Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors safepay

Description

SafePay emerged in September 2024 as a rapidly growing ransomware operation that explicitly disavows the RaaS model and manages all operations internally, claiming over 300 victims worldwide by mid-2025 with a high-profile early attack against UK telematics firm Microlise stealing 1.2 TB of data. Known victims: 462 2 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

SafePay is a medium-sophistication criminal threat actor specializing in ransomware operations. Known for its rapid growth and internal management of all operations, SafePay has targeted over 462 victims globally across various sectors. Its primary motivations include financial gain through ransomware activities.

Goals & Targeting

SafePay's strategic objectives are centered around financial gain through ransomware operations. The group targets organizations across multiple sectors, with a particular focus on entities that possess valuable data or services that can be disrupted for monetary gain. Its victims include both small and large businesses, reflecting an opportunistic approach to maximizing profit from each attack. By avoiding the RaaS model, SafePay retains control over its operations, allowing it to adapt quickly to defensive measures and maximize its attack success rate.

Enhanced Description

SafePay emerged as a significant ransomware operation in September 2024, quickly rising to prominence by managing its own infrastructure and avoiding the Ransomware-as-a-Service (RaaS) model. By mid-2025, SafePay had already claimed over 300 victims worldwide, with one of its earliest and most notable attacks being against a UK-based telematics firm, Microlise, from which it stole 1.2 TB of sensitive data. The group's operational independence has allowed it to maintain a high level of autonomy, enabling rapid proliferation and adaptability in its attack campaigns. SafePay's victims span various industries, including critical infrastructure, healthcare, and commercial sectors, reflecting its broad targeting strategy.

Key Capabilities

  • Internal ransomware operation management
  • Network intrusion capabilities
  • Data exfiltration techniques
  • Sophisticated encryption methods for ransomware deployment

MITRE ATT&CK Tactics

Exfiltration
Propagation
Impact
Network Access

ATT&CK Techniques

T1566.001
T1573.002
T1548.001
T1059.003

Campaigns & Victims

SafePay has demonstrated a highly active and aggressive campaign pattern, with a rapid increase in the number of victims shortly after its emergence. The group's ability to independently manage its operations has allowed it to maintain a high operational tempo, frequently targeting new victims across different regions and industries. Notable campaigns include attacks on critical infrastructure, healthcare providers, and commercial entities. SafePay's use of internal tools and lack of affiliations with known RaaS groups make its campaigns distinct but challenging to attribute.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • Network-based lateral movement using legitimate-looking protocols
  • Encrypted files with specific ransomware signatures in file extensions
  • Command and control (C2) communication via encrypted channels

Recommended Actions

  • Implement robust email filtering to detect phishing attempts
  • Enhance endpoint detection and response capabilities
  • Regularly back up critical data and isolate backups from network access
  • Conduct employee training on recognizing suspicious emails and links

Suggested Tags

Ransomware
Financial-gain
Criminal
Medium-sophistication

Confidence Assessment

Confidence in the data regarding SafePay's operational details is high, given its active campaign history and numerous victims. However, specific technical details about its tools and infrastructure remain limited, which introduces some uncertainty in accurately identifying all associated IOCs.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

110

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
Financial-gain
Criminal
Medium-sophistication

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Nov 10, 2023
Last Seen
Aug 3, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.