Ransomware Group intelligence
Safepay
ActiveTrack Safepay with 616 published victims and 5 known leak locations in a single intelligence view.
Overview
Safepay is tracked by Breach House as a ransomware group with 616 published victims.
United States is currently the most targeted country in this dataset.
5 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 0 0.0%
- Pending 139 99.3%
- Deleted 1 0.7%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (5)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 5 | Onion service | Up checked 3h ago | safepaypfxntwixwjrlcscft433ggemlhgkkdupi2ynhtcmvdgubmoyd.onion |
| Leak location 4 | Onion service | Down checked 3h ago | j3dp6okmaklajrsk6zljl5sfa2vpui7j2w6cwmhmmqhab6frdfbphhid.onion |
| Leak location 3 | Onion service | Down checked 3h ago | nj5qix45sxnl4h4og6hcgwengg2oqloj3c2rhc6dpwiofx3jbivcs6qd.onion |
| Leak location 2 | Onion service | Down checked 3h ago | cqkrkmmivhakl3fwgxscurduu3znmroablt7jskxszkctixyseij5gad.onion |
| Leak location 1 | Onion service | Down checked 3h ago | nz4z6ruzcekriti5cjjiiylzvrmysyqwibxztk6voem4trtx7gstpjid.onion |
Top Activity Sectors (16)
- Not identified 144
- Communication / Marketing 93
- Manufacturing / Engineering 54
- Services 38
- Construction / Real Estate 31
- IT 30
- Healthcare / Pharma 28
- Finance / Legal / Insurance 27
- Education 25
- Retail / E-commerce 22
- Agriculture / Food 15
- Transportation / Travel / Logistics 14
- Public Sector 13
- Hospitality / Food & Beverage / Tourism 12
- NGOs / Associations 9
- Energy 4
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Safepay, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: safepay executes PowerShell scripts to run payload logic, disable defenses, and stage ransomware components.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: safepay uses registry run keys and startup folders to maintain persistence after reboot.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: safepay disables or modifies security tools such as antivirus and monitoring agents to prevent detection and cleanup.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1688 Safe Mode Boot Defense Impairment
What they do: safepay attempts safe mode boot manipulation to disrupt recovery workflows and evade host-based defenses.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1027.016 Junk Code Insertion Stealth
What they do: safepay inserts junk code into binaries to evade static analysis and signature-based detection.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: safepay deletes Volume Shadow Copies and temporary files to eliminate recovery options and reduce forensic traces.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1135 Network Share Discovery Discovery
What they do: safepay uses network share discovery to locate victim file shares and staging directories for encryption targets.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: safepay moves laterally through SMB/Windows Admin Shares to encrypt additional systems across the network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: safepay encrypts victim files and backups using its ransomware payload to maximize impact and extortion leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1491.001 Internal Defacement Impact
What they do: safepay performs internal defacement by replacing or corrupting victim files to demonstrate impact and pressure victims.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Tools Observed (8)
▼Software Safepay has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Discovery
Exfiltration
LOLBAS (living-off-the-land binaries)
RMM Tools
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
readme_safepay.txt
Greetings! Your corporate network was attacked by SafePay team. Your IT specialists made a number of mistakes in setting up the security of your corporate network, so we were able to spend quite a long period of time in it and compromise you. It was the misconfiguration of your network that allowed our experts to attack you, so treat this situation as simply as a paid training session for your system administrators. We ve spent the time analyzing your data, including all the sensitive and confidential information. As a result, all files of importance have been encrypted and the ones of most interest to us have been stolen and are now stored on a secure server for further exploitation and publication on the Web with an open access. Now we are in possession of your files such as: financial statements, intellectual property, accounting records, lawsuits and complaints, personnel and customer files, as well as files containing information on bank details, transactions and other internal documentation. Furthermore we successfully blocked most of the servers that are of vital importance to you, however upon reaching an agreement, we will unlock them as soon as possible and your employees will be able to resume their daily duties. We are suggesting a mutually beneficial solution to that issue. You submit a payment to us and we keep the fact that your network has been compromised a secret, delete all your data and provide you with the key to decrypt all your data. WE ARE THE ONES WHO CAN CORRECTLY DECRYPT YOUR DATA AND RESTORE YOUR INFRASTRUCTURE IN A SHORT TIME. DO NOT TRY TO DECRYPT YOUR FILES YOURSELF, YOU WILL NOT BE ABLE TO DO THIS, YOU WILL ONLY DAMAGE THEM AND WE WILL NOT BE ABLE TO RESTORE THEM. In the event of an agreement, our reputation is a guarantee that all conditions will be fulfilled. No one will ever negotiate with us later on if we don't fulfill our part and we recognise that clearly! We are not a politically motivated group and want nothing more than money. Provided you pay, we will honour all the terms we agreed to during the negotiation process. In order to contact us, please use chat below, you have 10 days to contact us, after this time a blog post will be made with a timer for 3 days before the data is published and you will no longer be able to contact us. To contact us follow the instructions: Install and run Tor Browser from https://www.torproject.org/download/ Go to http://dgcg5ncjab6scb7fnk7gx5php4lbpxjy2jjnu3apnkxyippqf6yhw3ad.onion Reserve Link: http://oxly5vxvvhi5fv5vsvj3kvlqeprbijitycqisylaxzf324bn7e4qr2ad.onion Log in with ID: [snip] Contact and wait for a reply, we guarantee that we will reply as soon as possible, and we will explain everything to you once again in more detail. Our blog: http://j3dp6okmaklajrsk6zljl5sfa2vpui7j2w6cwmhmmqhab6frdfbphhid.onion http://nz4z6ruzcekriti5cjjiiylzvrmysyqwibxztk6voem4trtx7gstpjid.onion Our TON blog: tonsite://safepay.ton You can connect through your Telegramm account.
readme_safepay_ascii.txt
Greetings! Your corporate network was attacked by SafePay team. Your IT specialists made a number of mistakes in setting up the security of your corporate network, so we were able to spend quite a long period of time in it and compromise you. It was the misconfiguration of your network that allowed our experts to attack you, so treat this situation as simply as a paid training session for your system administrators. We ve spent the time analyzing your data, including all the sensitive and confidential information. As a result, all files of importance have been encrypted and the ones of most interest to us have been stolen and are now stored on a secure server for further exploitation and publication on the Web with an open access. Now we are in possession of your files such as: financial statements, intellectual property, accounting records, lawsuits and complaints, personnel and customer files, as well as files containing information on bank details, transactions and other internal documentation. Furthermore we successfully blocked most of the servers that are of vital importance to you, however upon reaching an agreement, we will unlock them as soon as possible and your employees will be able to resume their daily duties. We are suggesting a mutually beneficial solution to that issue. You submit a payment to us and we keep the fact that your network has been compromised a secret, delete all your data and provide you with the key to decrypt all your data. WE ARE THE ONES WHO CAN CORRECTLY DECRYPT YOUR DATA AND RESTORE YOUR INFRASTRUCTURE IN A SHORT TIME. DO NOT TRY TO DECRYPT YOUR FILES YOURSELF, YOU WILL NOT BE ABLE TO DO THIS, YOU WILL ONLY DAMAGE THEM AND WE WILL NOT BE ABLE TO RESTORE THEM. In the event of an agreement, our reputation is a guarantee that all conditions will be fulfilled. No one will ever negotiate with us later on if we don't fulfill our part and we recognise that clearly! We are not a politically motivated group and want nothing more than money. Provided you pay, we will honour all the terms we agreed to during the negotiation process. In order to contact us, please use chat below, you have 10 days to contact us, after this time a blog post will be made with a timer for 3 days before the data is published and you will no longer be able to contact us. To contact us follow the instructions: Install and run Tor Browser from https://www.torproject.org/download/ Go to http://dgcg5ncjab6scb7fnk7gx5php4lbpxjy2jjnu3apnkxyippqf6yhw3ad.onion Reserve Link: http://oxly5vxvvhi5fv5vsvj3kvlqeprbijitycqisylaxzf324bn7e4qr2ad.onion Log in with ID: [snip] Contact and wait for a reply, we guarantee that we will reply as soon as possible, and we will explain everything to you once again in more detail. Our blog: http://j3dp6okmaklajrsk6zljl5sfa2vpui7j2w6cwmhmmqhab6frdfbphhid.onion http://nz4z6ruzcekriti5cjjiiylzvrmysyqwibxztk6voem4trtx7gstpjid.onion Our TON blog: tonsite://safepay.ton You can connect through your Telegramm account.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (616)
Search, filter and paginate the victim timeline for Safepay. Showing 601–616 of 616.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | ccseniorservices id15513 View details | United States | Services | — | — | |
|
ZIP-50GB |
||||||
| Ransomware | ib-spieth.de id15512 View details | Germany | Other | — | — | |
|
ZIP-415B - Revenue $5 Million |
||||||
| Ransomware | Safex.us id15511 View details | United States | Other | — | — | |
|
ZIP-70GB - Revenue $5,4 Million |
||||||
| Ransomware | millerservicecompany.com id15510 View details | United States | Services | — | — | |
|
ZIP-70GB |
||||||
| Ransomware | mcauslan.com id15509 View details | Canada | Other | — | — | |
|
ZIP-50GB - Revenue $16.1 Million |
||||||
| Ransomware | stats.gov.bb id15508 View details | Barbados | Other | — | — | |
|
ZIP-330GB - Revenue $14.5 Million |
||||||
| Ransomware | smartdimensions id15507 View details | United States | Other | — | — | |
|
ZIP-18GB - Revenue $<5 Million |
||||||
| Ransomware | westwood id15506 View details | United States | Other | — | — | |
|
ZIP-50GB - Revenue $8.1 Million |
||||||
| Ransomware | threadfxinc/bluedogmerch id15505 View details | United States | Services | — | — | |
|
ZIP-70GB - Revenue $10.7 Million |
||||||
| Ransomware | Pronatec id15504 View details | Switzerland | Communication / Marketing | — | — | |
|
Revenue $5 Million |
||||||
| Ransomware | Gilazo id15503 View details | Israel | Other | — | — | |
|
Revenue $5 Million |
||||||
| Ransomware | OMINT id15502 View details | Argentina | Other | — | — | |
|
Revenue $540.7 Million |
||||||
| Ransomware | NKCE Japan id15501 View details | Japan | Manufacturing / Engineering | — | — | |
|
[AI generated] NKCE Japan is a company known for its expertise in engineering and manufacturing, specializing in precision components and advanced technological solutions. It serves various industries, providing high-quality products and innovative services. NKCE Japan is committed to excellence and customer satisfaction, leveraging cutting-edge technology and skilled craftsmanship to meet diverse client needs. |
||||||
| Ransomware | Richmond Hill Primary Academy id15500 View details | United Kingdom | Education | — | — | |
|
[AI generated] Richmond Hill Primary Academy is an educational institution focused on providing a nurturing and dynamic learning environment for children. It emphasizes academic excellence, personal growth, and community engagement. The academy offers a broad curriculum designed to foster creativity, critical thinking, and a love for learning, supported by a dedicated team of educators and staff. |
||||||
| Ransomware | Active Cosmetic id15499 View details | Argentina | Other | — | — | |
|
Revenue $26.7 Million |
||||||
| Ransomware | O'mara id15498 View details | Ireland | Other | — | — | |
|
Revenue $5.7 Million |
||||||