SafePay Ransomware Hits 73 Organizations in Just One Month
## Cybersecurity: SafePay Ransomware Group Overview
Cybersecurity: SafePay Ransomware Group Overview
SafePay, a prominent ransomware group, has gained significant attention in 2025 due to its increased activity and unique operational model. In June, SafePay targeted 73 organizations, leading Bitdefender’s Threat Debrief rankings. In July, the group added 42 more victims, resulting in over 270 claimed victims within the year.
SafePay emerged in September 2024, following law enforcement actions against other ransomware operations. The group's ransomware shares code similarities with LockBit Black, particularly in its use of the ChaCha20 encryption algorithm. Unlike LockBit, SafePay generates unique symmetric keys for each file and embeds a master key within the ransomware. SafePay operates independently, rejecting the affiliate model common among other ransomware groups.
SafePay maintains a closed operational model, controlling its operations and profits without involving third-party affiliates. This approach reduces the risk of code leaks and insider threats, allowing the group to demand higher ransom payments. The group’s public presence is limited to a data leak site listing victims following encryption.
SafePay targets mid-size and enterprise organizations across various regions, including the United States, Germany, Great Britain, and Canada. Industries affected include manufacturing, healthcare, construction, education, research, government, and technology services. The group’s attacks often result in rapid encryption, with organizations transitioning from initial access to full encryption within 24 hours.
SafePay, a prominent ransomware group, has gained significant attention in 2025 due to its increased activity and unique operational model.
Initial Access: Credential brute-forcing, VPN exploitation, and social engineering. Discovery: Network share enumeration using scripts like ShareFinder. Lateral Movement: Use of PsExec and remote management tools. Exfiltration: Data compression with WinRAR and transfer via FileZilla. Ransomware Deployment: Shadow copy deletion, encryption with .safepay extension, and delivery of ransom notes. Defense Evasion: Anti-debugger detection and termination of security processes.
Victims are given a unique ID for negotiations and have ten days to pay in Bitcoin before data is leaked.
Enforce multi-factor authentication for all access. Regularly update and patch critical infrastructure and VPN appliances. Implement strong password policies. Use advanced threat intelligence platforms like Bitdefender IntelliZone. Employ continuous monitoring with incident investigation capabilities. Harden systems using behavioral-analysis tools to reduce attack surfaces.
As SafePay's activities persist, organizations must strengthen their defenses and prepare for potential ransomware threats.
Based on reporting by GBHackers.
