SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltration — Threadlinqs Intelligence
As of 2026-07-27, SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltration is a high-severity ransomware threat attributed to Safepay (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1728 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: Safepay · Russia · FINANCIAL
SafePay ransomware operators breached a victim network via a FortiGate SSL-VPN misconfiguration that allowed a weak, MFA-lacking local-admin account to authenticate remotely, then after their
Sygnia's DFIR investigation documents a SafePay ransomware intrusion spanning roughly seven days, from initial VPN access to full-network encryption. The threat actor gained initial access through a FortiGate SSL-VPN account that was intended only for local appliance administration but was, contrary to its design intent, both domain-enabled and permitted to authenticate over VPN — with a weak password and no multi-factor authentication. Within hours of that initial foothold, the actor escalated to domain administrator. They then conducted methodical Active Directory and network discovery using native Windows utilities (nslookup.exe, ping.exe, powershell.exe, dsa.msc, ServerManager.exe), custom Python/PowerShell/batch scripts (RouteCIDR.py, p.bat_S.bat, p.bat_W.bat, check.ps1, search.ps1, sorted.ps1), and open-source AD attack tooling — Snaffler for credential and sensitive-file discovery, SharpShares and ShareFinder for network share enumeration, and Advanced IP Scanner for host discovery. Lateral movement was carried out primarily via RDP, supplemented by administrative share traversal (C$, ADMIN$) and direct interaction with Hyper-V hosts and the vCenter console, giving the actor reach across backup, virtualization, file, and identity infrastructure.
Having staged victim data, the actor first attempted exfiltration via FileZilla FTP to 192.166.225.69; this outbound connection was blocked by the victim's egress controls. Rather than retry a conspicuous channel, the actor pivoted to a technique that is materially new for SafePay: they installed the legitimate OneDrive sync client on a compromised host, authenticated to an attacker-controlled Microsoft 365 tenant (surfaced in browser history as jjvq-sharepoint.com / jjvq-my-sharepoint.com), and synchronized staged data into that tenant's OneDrive for Business instance (backed by SharePoint Online). Because the resulting traffic is HTTPS to a Microsoft cloud endpoint, it blends with routine, trusted enterprise cloud usage and is far less likely to trip egress-based DLP or network-anomaly detections than FTP or a bespoke exfiltration tool. Forensic recovery of orphaned MFT entries in the attacker's OneDrive account included RAR archives referencing other organizations' names (e.g., partially-redacted identifiers matching publicly claimed SafePay victims), indicating this same attacker-controlled tenant was used as shared staging infrastructure across multiple, separate SafePay intrusions — a durable piece of cross-victim correlation infrastructure rather than a one-off channel.
Impact was delivered via a locker.dll payload executed through regsvr32.exe (a signed-binary proxy execution technique that evades application allowlisting focused on standalone executables), persisted via an HKCU Run-key registry entry, and resulted in encryption of more than 60 servers with the .safepay extension and readme_safepay.txt ransom notes dropped throughout. SafePay itself is an independent (non-RaaS, non-affiliate) ransomware operation first observed in September–October 2024 that rapidly scaled through 2025 to become, for a period, the most active ransomware operation globally; its leak site had publicly claimed over 500 victims by mid-2026 (517 as of 2026-07-20, including 42 published that month and 73 in the preceding month), with victims skewing heavily toward small-and-mid-sized businesses in the United States and Germany across professional services, construction, healthcare, manufacturing, education, and government. Its encryptor is built on leaked LockBit 3.0 source with substantial rework and incorporates hybrid ChaCha20/AES file encryption with RSA/x25519 key wrapping; the group is broadly assessed (with low confidence) as Russia/CIS-linked based on a keyboard-locale kill switch that halts execution on Cyrillic-configured systems, though no confirmed nation-state attribution exists. Beyond this incident's specific tooling, SafePay's broader arsenal documented across vendor reportin
Target sectors: professional-services, construction, health, manufacturing, education, government administration, agriculture, energy, finance, hospitality, insurance, retail
Target regions: united states of america, germany, North America, 155 - Western Europe, Europe, Asia, Middle East, Oceania, 005 - South America
Detections & IOCs
As of 2026-08-17, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1650, T1190, T1133, T1078.002, T1059.001, T1059.003, T1059.006, T1547.001, T1548.002, T1218.010