SafePay is a ransomware operation active since the second half of 2024. It conducts double-extortion attacks, stealing data before encrypting victim systems and using public victim claims to apply pressure. SafePay has targeted organizations across manufacturing, food production, technology, professional services, and logistics-related operations, including victims in the United States, Italy, Spain, Israel, and South Korea. In a documented intrusion, SafePay exploited an internet-facing FortiGate SSL VPN weakness and an overprivileged administrative account without MFA, rapidly obtained domain-administrator privileges, and performed reconnaissance and lateral movement using RDP, administrative shares, PowerShell, native Windows functionality, and open-source tooling. The operation identified valuable file shares and credentials, targeted backup and virtualization infrastructure including Veeam, staged and compressed data, and exfiltrated it through an attacker-controlled Microsoft 365 tenant using the legitimate OneDrive synchronization client over HTTPS after an FTP-based attempt was blocked. SafePay subsequently executed a malicious DLL through a signed Windows utility, established Run-key persistence, and encrypted more than 60 servers, including identity, backup, virtualization, and file-storage systems. SafePay is also referred to as SafePay Team and SafePay ransomware group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
25 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted data exfiltration by abusing OneDrive, blending transfers into legitimate HTTPS traffic and normal business operations to evade conventional security controls.
A double-extortion ransomware operation active since the second half of 2024. In the described incident, it exploited a FortiGate SSL VPN weakness together with a weak overprivileged account without MFA; used native tools and open-source utilities for reconnaissance and lateral movement; staged data in multipart RAR archives; and, after FTP exfiltration was blocked, used the legitimate OneDrive client authenticated to an attacker-controlled Microsoft 365 tenant to exfiltrate data over HTTPS. It then deployed a malicious DLL through regsvr32.exe, established Run-key persistence, and encrypted more than 60 servers.
Groupe de ransomware figurant parmi les principaux acteurs recensés en juillet 2026.
A ransomware group included among the principal groups attributed to July 2026 attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.