BushidoUK ToolMatrix GroupProfiles: SafePay

Fecha
18 Jun 2026
Actor
bushidouk
Tipo
Report
Pais
United States
Sector
Defense
Confianza
high
60
Prioridad analitica
Media

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

2IOCs
0TTPs
bushidoukActor
United StatesPais
Executive Summary
Recurso del BushidoUK Ransomware Tool Matrix - GroupProfiles.

Key Points

  • Source: GroupProfiles/SafePay.md
  • BushidoUK Tool Matrix

GroupProfiles: SafePay.md

Recurso del BushidoUK Ransomware Tool Matrix - GroupProfiles.

SafePay's Tools

| Discovery | RMM Tools | Defense Evasion | Credential Theft | OffSec | Networking | LOLBAS | Exfiltration |

|---|---|---|---|---|---|---|---|

| Invoke-ShareFinder | Microsoft RDP | | | | | Regsvr32.exe | FileZilla |

| | | | | | | CMSTPLUA | 7zip |

| | | | | | | dllhost.exe | WinRAR |

> [!NOTE]

> This is the list of tools that have been observed during various intrusions that lead to SafePay ransomware deployment.

#### Sources

| Date Published | Report |

|---|---|

| 24 November 2024 | It's Not Safe to Pay SafePay |

Referencias

Diamond Model

Adversary
bushidouk
Ver perfil →
Victim
BushidoUK ToolMatrix GroupProfiles: SafePay
United States
Capability
Report
Infrastructure
Sin infraestructura confirmada

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
File Regsvr32.exe Artefacto observado VT OffSec SOCRadar
File dllhost.exe Artefacto observado VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor bushidouk en el blog → Ver bushidouk en IntelTracker → Fuente OSINT: github.com→ Fuente OSINT: github.com → Buscar bushidouk en APTTrail → Repositorio APTTrail → Mas incidentes en United States → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes