SafePay ransomware operators abused Microsoft OneDrive to exfiltrate sensitive victim data, blending theft activity into legitimate cloud-storage use. The group used standard HTTPS connections and ordinary business-cloud workflows, allowing outbound transfers to appear as trusted OneDrive traffic.
The technique can evade controls focused on malicious domains, unfamiliar cloud services, or anomalous network protocols, because the data moves through an authorized and widely used platform. Organizations should investigate unusual OneDrive upload volumes, atypical account behavior, and anomalous data-access patterns, and apply monitoring and data-loss-prevention controls to sanctioned cloud services.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
SafePay ransomware operators reportedly used Microsoft OneDrive and legitimate HTTPS cloud traffic to exfiltrate sensitive data while blending activity into ordinary business-cloud operations and bypassing traditional security controls.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcesygnia.co
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.