CiberLATAMbywhalemate

Mexico: SAFEPAY Added Auromex

SAFEPAY added Mexican manufacturer Auromex to its leak site. Security Arsenal also documented the group’s TTPs, and a note cited SCILabs.

Whalemate Labs · AI-assisted researchPublished:2 min read

SAFEPAY added auromex.com, a Mexico-based organization, to the victims listed on its leak site, according to Security Arsenal. The threat intelligence firm also placed it in the manufacturing sector and detailed techniques already seen in the operation. Separately, a note based on SCILabs said Mexico accounted for 17.93% of ransomware attacks recorded in Latin America in the first half of 2026.

SAFEPAY added auromex.com, a Mexico-based organization, to the victims listed on its leak site, according to Security Arsenal. The firm placed it in the manufacturing sector and described it as a confirmed case of ransomware or extortion tied to Mexico. In the same analysis, it also outlined the techniques the group has been using.

What is known about the Auromex case?

Security Arsenal said auromex.com appears among the latest additions to SAFEPAY’s leak site and that it is a manufacturing target in Mexico. That identifies the case as a confirmed victim within the campaign attributed to the group. No further public details were released about the specific incident in the available material.

What techniques did Security Arsenal document?

Security Arsenal said SAFEPAY’s documented TTPs include initial access through edge devices or VPNs, phishing macro execution, lateral movement with PsExec and WMI, credential dumping, and pre-encryption activity along with shadow copy destruction. Together, those tactics point to an operation that combines initial intrusion, internal spread, and actions meant to make recovery harder. The report did not attribute those techniques to a single case, but to the group’s observed behavior.

What does the regional reference say about Mexico?

A note from El Destape Web, citing SCILabs, said Mexico accounted for 17.93% of ransomware attacks recorded in Latin America during the first half of 2026, equal to 52 of 290 cases in the region. The same note, also based on SCILabs, identified financial services and telecoms as the most exposed sectors in the country. It also said many Mexican SMEs still rely on legacy technology and weak patching and cybersecurity programs.

Sources

View all