Back to Ransomware Database
Ransomware Group
safepay
SafePay emerged in September 2024 as a rapidly growing ransomware operation that explicitly disavows the RaaS model and manages all operations internally, claiming over 300 victims worldwide by mid-2025 with a high-profile early attack against UK telematics firm Microlise stealing 1.2 TB of data.
Known victims569
Threat Level
CRITICAL
Tactics, Techniques & Procedures (TTPs)
DiscoveryEnum
- Invoke-ShareFinder
Exfiltration
- 7-Zip
- WinRAR
LOLBAS
- CMSTPLUA
- Regsvr32.exe
- dllhost.exe
Check If You’re Affected
Search our database to see if your organization appears in safepay’s victim list.
Try it nowFree⌘K
Try
risk score · threat categories · sources · age · confidence — in one request