{"id":6710,"date":"2025-09-06T10:04:11","date_gmt":"2025-09-06T10:04:11","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/06\/safepay-ransomware-claiming-attacks-over-73-victim-organizations-in-a-single-month\/"},"modified":"2025-09-06T10:04:11","modified_gmt":"2025-09-06T10:04:11","slug":"safepay-ransomware-claiming-attacks-over-73-victim-organizations-in-a-single-month","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/06\/safepay-ransomware-claiming-attacks-over-73-victim-organizations-in-a-single-month\/","title":{"rendered":"SafePay Ransomware Claiming Attacks Over 73 Victim Organizations in a Single Month"},"content":{"rendered":"<p>    SafePay Ransomware Claiming Attacks Over 73 Victim Organizations in a Single Month<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A new ransomware threat has emerged as one of 2025\u2019s most prolific cybercriminal operations, with SafePay ransomware claiming attacks against 73 victim organizations in June alone, followed by 42 additional victims in July.<\/p>\n<p>This surge has positioned SafePay as a significant threat actor that security teams worldwide must understand and prepare to defend against.<\/p>\n<p>Unlike traditional <a href=\"https:\/\/cybersecuritynews.com\/ransomware-as-a-service-raas-evolved-as-a-predominant-framework\/\" target=\"_blank\" rel=\"noreferrer noopener\">ransomware-as-a-service<\/a> (RaaS) models that rely on affiliate networks, SafePay operates as a closed, independent group that maintains strict operational security.<\/p>\n<p>The group\u2019s rapid-fire attack methodology has proven remarkably effective, with more than 270 claimed victims documented throughout 2025.<\/p>\n<p>Their operations target primarily mid-size and enterprise organizations across the United States, Germany, Great Britain, and Canada, focusing on industries critical to daily operations including manufacturing, healthcare, and construction.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjcrOqW3qTkq0V8EZ93_M8BCJErevLnF3wzPx9rJ4bKzHAP-jttQMpGW_cHRU9HmsQQS7hHKcgUy2kEYcyJEqU8uitQXgOuKpcp_zNWZkyB752UXY-JyEXPxkTHXId3yObNNn2yv5218bhAR2MCTi7ZLtP4FsqzARNL12cgjXSFHTXqBUl-WfxDG91xAII\/s16000\/Most%2520affected%2520industries%2520%28Source%2520-%2520Bitdefender%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Most affected industries (Source \u2013 Bitdefender)<\/figcaption><\/figure>\n<\/div>\n<p>The group\u2019s emergence can be traced back to September 2024, arising in the aftermath of significant law enforcement operations that dismantled ALPHV (Black Cat) and severely disrupted LockBit\u2019s infrastructure through Operation Cronos.<\/p>\n<p>Bitdefender analysts <a href=\"https:\/\/www.bitdefender.com\/en-us\/blog\/businessinsights\/safepay-ransomware-attacks-ttps\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> parts of the SafePay ransomware that complement functionalities associated with LockBit, specifically LockBit Black, though the groups operate with distinctly different methodologies and encryption processes.<\/p>\n<p>SafePay demonstrates an alarming capability to execute complete attack chains within 24-hour periods, moving from initial access through encryption with devastating efficiency.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjIT8J_oJ1C7cAvY_joUhPqoVMPnnc5NKnI_FaOh9N_KZ4veWzuOrsf9YBB1l68xyulHdJgHm49_GY0jn3K76tQ6XsJTDrlz_E5b3oBZ-zABkokncNuq_5cUzmGMtBq6S_usj9b8WXTUAsLzrELQks0fOYG4t7WX_2WN2t7VtJBloq40yZAv8q5CHaLfuc\/s16000\/SafePay%25E2%2580%2599s%2520Victims%2520Claimed%2520Per%2520Day%2520%28Source%2520-%2520Bitdefender%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">SafePay\u2019s Victims Claimed Per Day (Source \u2013 Bitdefender)<\/figcaption><\/figure>\n<\/div>\n<p>Their victim selection appears methodical, targeting organizations with revenues typically around $5 million, though outliers include entities with revenues exceeding $100 million and one victim surpassing $40 billion in revenue.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-encryption-and-evasion-mechanisms\"><strong>Encryption and Evasion Mechanisms<\/strong><\/h2>\n<p>SafePay employs sophisticated technical approaches that distinguish it from other ransomware families.<\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> utilizes the ChaCha20 encryption algorithm, implementing unique symmetric keys for each encrypted file while embedding additional keys directly within the ransomware executable.<\/p>\n<p>This dual-key approach complicates recovery efforts and ensures that each victim\u2019s encryption remains uniquely secured.<\/p>\n<p>The ransomware demonstrates advanced defense evasion capabilities, including debugger detection avoidance and the ability to terminate processes associated with <a href=\"https:\/\/cybersecuritynews.com\/av-detection-anti-malware-scans-bypassed\/\" target=\"_blank\" rel=\"noreferrer noopener\">anti-malware<\/a> functions.<\/p>\n<p>Upon execution, <a href=\"https:\/\/cybersecuritynews.com\/safepay-ransomware-leverages-rdp-and-vpn\/\" target=\"_blank\" rel=\"noreferrer noopener\">SafePay<\/a> immediately begins removing volume shadow copies to prevent system restoration, then proceeds to encrypt files with the .safepay extension while deploying ransom notes named \u201creadme_safepay.txt\u201d in affected directories.<\/p>\n<p>One notable technical characteristic involves the malware\u2019s geographic targeting logic.<\/p>\n<p>SafePay performs language keyboard detection to identify systems using Cyrillic keyboards, preventing execution on these systems, suggesting potential Russian connections or alliances within the threat actor ecosystem.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/safepay-ransomware-claiming-attacks-over-73-victim\/\">SafePay Ransomware Claiming Attacks Over 73 Victim Organizations in a Single Month<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/safepay-ransomware-claiming-attacks-over-73-victim\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SafePay Ransomware Claiming Attacks Over 73 Victim Organizations in a Single Month A new ransomware threat has emerged as one of 2025\u2019s most prolific cybercriminal operations, with SafePay ransomware claiming attacks against 73 victim organizations in June alone, followed by 42 additional victims in July. This surge has positioned SafePay as a significant threat actor [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6710","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6710"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6710"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6710\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6710"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6710"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6710"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}