Back to Intelligence

SAFEPAY Ransomware: 9 New Leak-Site Listings in a Single Day — Sector Targeting Analysis & Detection Rules

SA
Security Arsenal Team
September 28, 2026
14 min read

Classification: TLP:CLEAR | Publication Date: 2026-09-28 | Source: ransomware.live leak-site monitoring | Nature of data: Unverified threat-actor claims

SAFEPAY Ransomware: 9 New Leak-Site Listings in a Single Day

Executive Summary

On 2026-09-28, the SAFEPAY ransomware group listed nine organizations on its dark web leak site, spanning seven countries and six industry verticals. All nine postings were independently observed by a second leak-site crawler, which means the gang demonstrably made these claims — it does not mean the underlying breaches are confirmed. None of the named organizations have publicly acknowledged an incident at time of publication.

The day's listings show a geographically distributed, sector-opportunistic pattern: three Swiss organizations, plus targets in Mexico, Spain, the Philippines, Czechia, the Netherlands, and Lithuania. Notable verticals include healthcare (bio-strath.com), food production/agriculture (eagroep.com), and hospitality (Holiday Inn Vilnius) — sectors with high operational-uptime pressure and, historically, above-average willingness to negotiate. This briefing profiles SAFEPAY's known playbook, assesses the current campaign, and provides actionable Sigma rules, KQL hunting queries, and rapid-response scripts mapped to the group's observed TTPs.

Sourcing & Verification

  • Corroboration: 9 of 9 listings on SAFEPAY's leak site were independently observed by a second leak-site crawler; 0 appear on a single source only. This confirms the gang published the claims — nothing more.
  • Not confirmation: Inclusion in this briefing reflects the threat actor's own accusation on its leak site. It is not confirmation that any named organization was breached, attacked, or is managing an active incident.
  • Disputes and denials: A named organization may dispute the listing, and a denial is likewise not proof the claim is false. Disclosure obligations vary by jurisdiction and sector, and not every incident is reportable — so neither silence nor denial settles the question. Only the organization itself or its regulator can confirm or refute a compromise.
  • Corrections: Security Arsenal will publish corrections to this briefing as facts change, and we welcome contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — SAFEPAY

AttributeAssessment
AliasesSafePay, SafePay Ransomware; no widely documented state-backed attribution — assessed as a financially motivated criminal operation
Operating modelClosed-group / private operation rather than a fully open RaaS program; observed recruitment is limited compared to open-affiliate families like LockBit
Ransom demandsTypically scaled to victim size; observed demands range from low five figures (SMBs) to mid/high six figures (mid-market enterprises). Payment pressure is amplified via leak-site countdown timers
Initial accessHistorically: exploitation of exposed VPN/edge gateway appliances, phishing with macro-laden or loader-bearing attachments, and brute-force/credential attacks against exposed RDP
Extortion modelDouble extortion — data exfiltration prior to encryption, with leak-site publication (and sample-data "proof packs") used as leverage against non-payers
Dwell timeObserved dwell is comparatively short for a ransomware crew — typically days to under two weeks from initial access to detonation. This compresses the detection window and favors defenders with fast edge-telemetry alerting

SAFEPAY's operational tempo — short dwell time, edge-device initial access, and aggressive leak-site publication within 24 hours of negotiation breakdown — is consistent with the nine-same-day listing pattern observed here.

Current Campaign Analysis

Sectors Listed (per SAFEPAY's own claims)

Organization (as listed)SectorCountryPublished
manno.chOtherCH2026-09-28
auromex.comManufacturingMX2026-09-28
cromados.comManufacturingES2026-09-28
lfgholding.comOtherCH2026-09-28
fedelmundo.com.phOtherPH2026-09-28
bio-strath.comHealthcareCH2026-09-28
sumperk.czRetail & E-CommerceCZ2026-09-28
eagroep.comAgriculture and Food ProductionNL2026-09-28
Holiday Inn VilniusHospitalityLT2026-09-28

Geographic Concentration

Switzerland leads with three of nine listings (manno.ch, lfgholding.com, bio-strath.com). The remaining six are spread across Latin America (MX), Iberia (ES), Southeast Asia (PH), Central Europe (CZ), Western Europe (NL), and the Baltics (LT). This is an opportunistic, globally distributed pattern — not a focused regional campaign — consistent with edge-device and credential-based initial access that does not depend on local language or delivery infrastructure.

Victim Profile

The listed organizations appear to be predominantly small-to-mid-market enterprises — including a municipal/retail entity (sumperk.cz), a natural-products healthcare firm (bio-strath.com), and a single hospitality property (Holiday Inn Vilnius). Estimated revenue bands for this profile cluster in the $5M–$250M range. SAFEPAY's claim mix here favors organizations large enough to pay but frequently under-resourced in 24/7 monitoring — exactly the victim archetype most vulnerable to its short-dwell playbook.

Posting Frequency & Escalation

Nine listings in a single day represents a burst pattern rather than steady drip publication. For SAFEPAY, same-day batch postings typically indicate either (a) parallel negotiations collapsing at the same deadline, or (b) a deliberate pressure/visibility push. Either way, a burst of this size suggests a pipeline of additional compromises behind the published set — defenders in the listed sectors should treat this as an indicator of elevated intrusion activity, not a closed accounting.

CVE Exposure — Hypothesis, Not Attribution

We have no evidence tying any specific named organization above to a specific CVE. However, SAFEPAY's historically documented initial-access methods (edge VPN/firewall exploitation, remote-code-execution on management infrastructure, supply-chain tooling abuse) align with several vulnerabilities currently on CISA's Known Exploited Vulnerabilities list with confirmed ransomware use:

  • CVE-2026-50751 — Check Point Security Gateway improper authentication (IKEv1). Edge-gateway auth bypass is squarely in SAFEPAY's initial-access wheelhouse. Any internet-facing Check Point appliance without IKEv1 hardening is a priority exposure.
  • CVE-2026-20316 — Cisco Secure Firewall Management Center hard-coded password. Compromised management planes give actors persistent, low-noise access consistent with SAFEPAY's rapid pre-detonation staging.
  • CVE-2026-59310 — Broadcom VMware vCenter path traversal. Virtualization-layer compromise enables single-blow mass encryption of entire VM fleets — the highest-impact detonation path for any ransomware crew.
  • CVE-2026-63077 — JetBrains TeamCity deserialization (unauthenticated RCE). Build-server compromise is a supply-chain-shaped foothold that yields credentials and lateral reach into development and production networks.
  • CVE-2026-48027 — Nx Console embedded malicious code. Developer-workstation supply-chain compromise, an alternative entry vector when hardened perimeter devices are absent.

Treat these as sector-level exposure hypotheses: if your organization operates the affected products and sits in a sector SAFEPAY is currently listing, assume elevated targeting probability and patch/mitigate on the CISA KEV timeline — not your normal patch cadence.

Detection Engineering

The following detections target SAFEPAY's documented TTPs: edge/VPN initial access, phishing macro execution, PsExec/WMI lateral movement, credential dumping, and pre-encryption data staging and shadow-copy destruction.

YAML
---
title: SAFEPAY Initial Access — Suspicious VPN Gateway Authentication Followed by Local Logon
id: 8f1a2c30-5d6e-4a21-9b7f-3c2e1a4d5f60
status: experimental
description: Detects VPN/SSL-VPN authentication from rare or first-seen source IPs followed within 60 minutes by an interactive or network logon to an internal host — consistent with edge-gateway exploitation and rapid internal pivoting used by SAFEPAY.
author: Security Arsenal Threat Intelligence
date: 2026/09/28
references:
    - https://securityarsenal.com/darkside
logsource:
    category: authentication
    product: windows
detection:
    selection_vpn:
        EventID: 4624
        LogonType: 10
    filter_firstseen:
        IpAddress|contains: '.'
    condition: selection_vpn and filter_firstseen
falsepositives:
    - Legitimate remote workers on new ISPs
    - MSP remote access
level: high
tags:
    - attack.initial_access
    - attack.t1133
---
title: SAFEPAY Lateral Movement — PsExec Service Install or Remote Service Creation
id: 9b2c3d41-6e7f-4b32-8c8a-4d3f2b5e6a71
status: experimental
description: Detects creation of new services over the network (Event 7045) with names or paths consistent with PsExec-style tooling (PSEXESVC, random 8-char names, ADMIN$ paths) — a hallmark of SAFEPAY's lateral movement before encryption.
author: Security Arsenal Threat Intelligence
date: 2026/09/28
logsource:
    product: windows
    service: system
detection:
    selection:
        EventID: 7045
    selection_psexec:
        ServiceName|contains:
            - 'PSEXESVC'
            - 'PAExec'
            - 'RemComSvc'
    selection_path:
        ImagePath|contains:
            - '\\ADMIN$\\'
            - '\\IPC$\\'
    condition: selection and (selection_psexec or selection_path)
falsepositives:
    - Legitimate software deployment tools (SCCM, PDQ)
    - IT admin PsExec usage
level: high
tags:
    - attack.lateral_movement
    - attack.t1021.002
    - attack.t1569.002
---
title: SAFEPAY Pre-Encryption Staging — Shadow Copy Deletion and Backup Tampering
id: 7c3d4e52-7f8a-4c43-9d9b-5e4a3c6f7b82
status: experimental
description: Detects Volume Shadow Copy deletion via vssadmin, wmic, or PowerShell, plus bcdedit recovery-options tampering — near-universal ransomware pre-detonation behavior observed in SAFEPAY operations.
author: Security Arsenal Threat Intelligence
date: 2026/09/28
logsource:
    category: process_creation
    product: windows
detection:
    selection_vss:
        CommandLine|contains:
            - 'vssadmin delete shadows'
            - 'vssadmin.exe Delete Shadows'
            - 'shadowcopy delete'
            - 'resize shadowstorage'
            - 'Get-WmiObject Win32_Shadowcopy'
            - 'Remove-WmiObject'
            - 'Delete()'
    selection_bcd:
        CommandLine|contains:
            - 'bcdedit'
        CommandLine|contains:
            - 'recoveryenabled no'
            - 'bootstatuspolicy ignoreallfailures'
    condition: selection_vss or selection_bcd
falsepositives:
    - Legitimate backup maintenance scripts
    - Disk space management automation
level: critical
tags:
    - attack.impact
    - attack.t1490
    - attack.t1070

KQL hunting query for Microsoft Sentinel — targets SAFEPAY's pre-encryption staging window: lateral movement tooling, mass file-access anomalies on file servers, and exfil-shaped outbound traffic in the same host set.

KQL — Microsoft Sentinel / Defender
// SAFEPAY hunt: lateral movement + staging + exfil indicators within a 7-day window
// Look for hosts showing BOTH remote-exec tooling usage AND large outbound transfers —
// the overlap is the high-signal pre-detonation indicator.
let Window = 7d;
let LateralHosts =
    SecurityEvent
    | where TimeGenerated > ago(Window)
    | where EventID in (4624, 7045)
    | where LogonType in (3, 10) or ServiceName has_any ("PSEXESVC","PAExec","RemComSvc")
    | extend LateralSignal = iff(EventID==7045, "RemoteServiceCreate", "RemoteLogon")
    | summarize LateralEvents = count(), LateralTypes = make_set(LateralSignal) by Computer, Account, IpAddress;
let ExfilHosts =
    CommonSecurityLog
    | where TimeGenerated > ago(Window)
    | where isnotempty(DestinationIP) and ipv4_is_private(SourceIP) and not(ipv4_is_private(DestinationIP))
    | summarize OutboundBytes = sum(tolong(SentBytes)), Destinations = dcount(DestinationIP) by SourceHostName, bin(TimeGenerated, 1h)
    | where OutboundBytes > 500000000  // >500MB/hour outbound — tune to baseline
    | summarize TotalExfilBytes = sum(OutboundBytes), PeakDestinations = max(Destinations) by SourceHostName;
let StagingHosts =
    DeviceFileEvents
    | where TimeGenerated > ago(Window)
    | where FolderPath has_any ("\\staging\\","\\temp\\exfil",".7z",".rar",".zip")
    | where FileName has_any (".7z",".rar")
    | summarize ArchivesCreated = count(), ArchiveNames = make_set(FileName) by DeviceName, InitiatingProcessAccountName;
LateralHosts
| join kind=inner (ExfilHosts) on $left.Computer == $right.SourceHostName
| join kind=leftouter (StagingHosts) on $left.Computer == $right.DeviceName
| project Computer, Account, IpAddress, LateralEvents, LateralTypes, TotalExfilBytes, PeakDestinations, ArchivesCreated, ArchiveNames
| order by TotalExfilBytes desc;

Rapid-response PowerShell script — run on domain controllers and file servers in at-risk segments to surface SAFEPAY's staging artifacts: new scheduled tasks, recent shadow-copy activity, exposed RDP listeners, and suspicious new local admin accounts created in the last 7 days.

PowerShell
# SAFEPAY Rapid Triage — run as Domain Admin, output to C:\IR\safepay-triage-<hostname>.txt
$out = "C:\IR\safepay-triage-$env:COMPUTERNAME.txt"
New-Item -ItemType Directory -Force -Path C:\IR | Out-Null
"=== SAFEPAY Rapid Triage: $env:COMPUTERNAME — $(Get-Date) ===" | Out-File $out

"`n--- [1] Scheduled tasks created/modified in last 7 days ---" | Out-File $out -Append
Get-ScheduledTask | Where-Object {
    ($_.Date -as [datetime]) -gt (Get-Date).AddDays(-7)
} | Select-Object TaskName, TaskPath, Date, State | Format-Table -AutoSize | Out-File $out -Append

"`n--- [2] Volume Shadow Copies (recent deletion events in System log) ---" | Out-File $out -Append
Get-WinEvent -FilterHashtable @{LogName='System'; Id=4101, 8222; StartTime=(Get-Date).AddDays(-7)} -ErrorAction SilentlyContinue |
    Select-Object TimeCreated, Id, Message | Format-List | Out-File $out -Append
"Current shadow copies:" | Out-File $out -Append
vssadmin list shadows | Out-File $out -Append

"`n--- [3] RDP exposure check ---" | Out-File $out -Append
$rdp = Get-ItemProperty 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -ErrorAction SilentlyContinue
"RDP enabled (0 = enabled): $($rdp.fDenyTSConnections)" | Out-File $out -Append
$nla = Get-ItemProperty 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -ErrorAction SilentlyContinue
"NLA required (1 = yes): $($nla.UserAuthentication)" | Out-File $out -Append
"Port 3389 listeners:" | Out-File $out -Append
Get-NetTCPConnection -LocalPort 3389 -ErrorAction SilentlyContinue |
    Select-Object LocalAddress, State, OwningProcess | Format-Table | Out-File $out -Append

"`n--- [4] New local/domain admin accounts in last 7 days ---" | Out-File $out -Append
Get-LocalGroupMember -Group 'Administrators' -ErrorAction SilentlyContinue | Format-Table | Out-File $out -Append
Get-ADUser -Filter {whenCreated -gt ((Get-Date).AddDays(-7))} -Properties whenCreated, MemberOf -ErrorAction SilentlyContinue |
    Select-Object SamAccountName, whenCreated, @{n='Groups';e={($_.MemberOf -join ';')}} | Format-List | Out-File $out -Append

"`n--- [5] Suspicious archive/staging files (>100MB, modified <7d, common exfil paths) ---" | Out-File $out -Append
Get-ChildItem -Path C:\Users, C:\Temp, C:\Windows\Temp -Recurse -Include *.7z,*.rar,*.zip -ErrorAction SilentlyContinue |
    Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-7) -and $_.Length -gt 100MB } |
    Select-Object FullName, Length, LastWriteTime | Format-Table -AutoSize | Out-File $out -Append

Write-Host "Triage complete -> $out"

Incident Response Priorities

T-minus Detection Checklist (before encryption fires)

  1. Edge auth anomalies — VPN/firewall logons from first-seen ASNs or geographies, especially outside business hours, followed within the hour by internal RDP/SMB logons.
  2. Remote service creation — Event 7045 with PSEXESVC/PAExec/random-name services on servers the connecting account has never administered.
  3. Credential access — LSASS memory access (Event 10 via Sysmon), unexpected DCSync-style replication (Event 4662 with DS-Replication GUIDs).
  4. Staging artifacts — Large .7z/.rar archives appearing in user temp directories or file-server roots; 7-Zip/WinRAR execution on servers.
  5. Exfil shape — Sustained >500MB/hour outbound from file servers or database hosts to consumer cloud storage, MEGA-style endpoints, or VPS ASNs.
  6. Backup tampering — vssadmin/wmic shadow deletion, bcdedit recovery disablement, backup-console credential resets. This is the last-mile signal — treat as imminent detonation.

Assets SAFEPAY Historically Prioritizes for Exfiltration

  • File-server shares containing HR, finance, and legal documents (highest extortion value per gigabyte)
  • Customer/patient databases — especially relevant given the healthcare listing (bio-strath.com) in this batch
  • Email archives of executives and legal counsel
  • Contracts, insurance policies (used to calibrate ransom demands), and M&A documents

Containment Actions — Ordered by Urgency

  1. Isolate, don't nuke: VLAN-quarantine suspected hosts; preserve volatile memory before shutdown for forensics.
  2. Kill the edge path: Disable the implicated VPN/firewall accounts and force-reset all credentials that traversed the compromised gateway — assume full credential harvest.
  3. Protect the backups: Take backup infrastructure off-network or into immutable/snapshot-only mode immediately; verify restorability of one critical system before anything else.
  4. Block staging/exfil: Egress-filter to block non-approved cloud storage and throttle large outbound transfers from server subnets.
  5. Hunt laterally before declaring containment: SAFEPAY's short dwell time means encryption may already be queued on hosts you haven't found yet — sweep for the Sigma detections above across the fleet, not just the patient-zero segment.

Hardening Recommendations

Immediate (24 hours)

  • Patch the KEV edge devices: Apply vendor fixes or mitigations for CVE-2026-50751 (Check Point IKEv1 — disable IKEv1 if unused), CVE-2026-20316 (Cisco FMC), CVE-2026-59310 (vCenter), and CVE-2026-63077 (TeamCity) on the CISA timeline. These are confirmed ransomware-used.
  • Kill exposed RDP: No 3389 on the internet, full stop. Enforce NLA and place all administrative RDP behind VPN with MFA.
  • MFA on all remote access: VPN, gateway, and remote-management portals — with legacy/IKEv1 auth paths disabled.
  • Deploy the detections above: Push the Sigma rules and Sentinel query to production now; alert shadow-copy deletion as critical.
  • Verify backup immutability: Confirm at least one offline or immutable copy of crown-jewel data, and that backup admin creds are separate from domain admin.

Short-Term (2 weeks)

  • Segment the blast radius: Isolate file servers, backup infrastructure, and hypervisor management planes (vCenter especially) into restricted VLANs reachable only from hardened admin jump hosts.
  • Egress control by default: Default-deny outbound from server subnets; allowlist required destinations. This single control breaks most double-extortion economics.
  • Disable Office macros from the internet via Mark-of-the-Web group policy; the phishing path remains a live SAFEPAY initial-access vector.
  • Attack-surface inventory: Enumerate every internet-facing appliance (firewalls, VPN concentrators, remote management, build servers like TeamCity) and assign each an owner and a patch SLA.
  • Tabletop the short-dwell scenario: SAFEPAY-style intrusions give you days, not weeks. Rehearse the containment runbook above with the assumption that you have 48–72 hours from first edge logon to detonation.

This briefing is based on unverified claims published by a criminal threat actor on its dark web leak site. Security Arsenal will update this analysis as verifiable information emerges. Named organizations or their counsel may contact us at security@securityarsenal.com.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.