Skip to content

SafePay

SafePay is a financially motivated ransomware operation and associated custom ransomware strain that emerged in late 2024 and became one of the more active extortion actors through 2025 and early 2026.

Profile source: Mallory opens in a new tab

SafePay

Family profile

SafePay is a financially motivated ransomware operation and associated custom ransomware strain that emerged in late 2024 and became one of the more active extortion actors through 2025 and early 2026. The group presents itself as a private, centralized operation rather than a ransomware-as-a-service program. It uses a double-extortion model, stealing victim data and then encrypting systems to pressure payment, with non-paying victims publicly exposed on its leak site. Reported victimology indicates broad cross-sector targeting, with repeated visibility in healthcare and notable activity against managed service providers and small-to-midsize businesses, as well as organizations in North America and Europe, especially the United States and Germany.

Observed intrusions show SafePay relying on conventional but effective human-operated tradecraft rather than highly novel techniques. Documented initial access includes password spraying against VPN infrastructure, followed by a dwell period before privilege escalation, internal discovery, data collection, exfiltration, and rapid encryption. Operators have used publicly available administrative and post-compromise tooling for share enumeration and data staging, searched for and encrypted backup resources, and deleted shadow copies to hinder recovery. In at least one investigated case, the actor obtained domain administrator privileges after a prolonged intrusion and completed collection, exfiltration, and encryption in a compressed final phase. The group has also been reported to directly contact victims by telephone to intensify extortion pressure.

The SafePay ransomware itself is a custom Windows encryptor written in C. Analysis has described asynchronous file encryption using Overlapped I/O, support for partial encryption, and conditional use of AES-CBC or ChaCha20 depending on processor support, with Curve25519 protecting per-file key material. Researchers assessing the malware found design similarities to several established ransomware families but concluded it was likely independently developed rather than a direct derivative. Operational reporting has also suggested that, at least during part of 2025, SafePay lacked a native VMware ESXi encryptor and instead carried out observed encryption activity from within guest virtual machines.

SafePay has been linked to multiple significant extortion incidents, including attacks affecting healthcare entities, government service providers, and large enterprises. Public reporting associates the group with major data theft and disruption events involving organizations such as Conduent and Ingram Micro. Across 2025, SafePay was repeatedly ranked among the more active ransomware brands by victim volume and was consistently identified as a notable threat to the healthcare sector.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Reconnaissance

Operational record

1
YARA rules
2
Ransom notes
5
Leak sites
1 available

Discovery Enum

  • Invoke-ShareFinder

Exfiltration

  • 7-Zip
  • WinRAR

LOLBAS

  • CMSTPLUA
  • Regsvr32.exe
  • dllhost.exe

Recent claims

Reported operators

Threat actors

1 named in public reporting
SafePay

The SafePay ransomware group is a relatively new group, first appearing on our radar in November 2024. The group follows a double-extortion scheme, both exfiltrating data and encrypting it on victim machines using their own SafePay ransomware.

MITRE ATT&CK

SafePay in ATT&CK

155 distinct techniques

Techniques

155 techniques
T1486 Data Encrypted for Impact T1041 Exfiltration Over C2 Channel T1074 Data Staged T1082 System Information Discovery T1490 Inhibit System Recovery T1110.003 Password Spraying T1048 Exfiltration Over Alternative Protocol T1078 Valid Accounts T1548.002 Bypass User Account Control T1078.002 Domain Accounts T1021.002 SMB/Windows Admin Shares T1531 Account Access Removal T1059.003 Windows Command Shell T1135 Network Share Discovery T1190 Exploit Public-Facing Application T1091 Replication Through Removable Media T1189 Drive-by Compromise T1566.001 Phishing: Spearphishing Attachment T1566.002 Phishing: Spearphishing Link T1566.003 Phishing: Spearphishing Voice T1047 Windows Management Instrumentation T1053.005 Scheduled Task/Job: Scheduled Task T1059 Command and Scripting Interpreter T1059.001 Command and Scripting Interpreter: PowerShell T1059.005 Command and Scripting Interpreter: Visual Basic T1106 Native API T1129 Shared Modules T1203 Exploitation for Client Execution T1204.001 User Execution: Malicious Link T1204.002 User Execution: Malicious File T1098 Account Manipulation T1505.004 Server Software Component: IIS Components T1542.003 Pre-OS Boot: Bootkit T1543.003 Create or Modify System Process: Windows Service T1547 Boot or Logon Autostart Execution T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder T1547.009 Boot or Logon Autostart Execution: Shortcut Modification T1574.001 Hijack Execution Flow: DLL Search Order Hijacking T1134.002 Access Token Manipulation: Create Process with Token T1134.004 Access Token Manipulation: Parent PID Spoofing T1014 Rootkit T1027 Obfuscated Files or Information T1027.002 Obfuscated Files or Information: Software Packing T1027.005 Obfuscated Files or Information: Indicator Removal from Tools T1027.007 Obfuscated Files or Information: Dynamic API Resolution T1027.009 Obfuscated Files or Information: Embedded Payloads T1027.013 Obfuscated Files or Information: Encrypted/Encoded File T1027.016 Obfuscated Files or Information: Junk Code Insertion T1036 Masquerading T1036.003 Masquerading: Rename Legitimate Utilities T1036.004 Masquerading: Masquerade Task or Service T1036.005 Masquerading: Match Legitimate Name or Location T1036.007 Masquerading: Double File Extension T1036.008 Masquerading: Masquerade File Type T1055 Process Injection T1055.001 Process Injection: DLL Injection T1070 Indicator Removal T1070.003 Indicator Removal: Clear Command History T1070.004 Indicator Removal: File Deletion T1070.006 Indicator Removal: Timestomp T1112 Modify Registry T1140 Deobfuscate/Decode Files or Information T1218 System Binary Proxy Execution T1218.004 System Binary Proxy Execution: InstallUtil T1218.005 System Binary Proxy Execution: Mshta T1218.007 System Binary Proxy Execution: Msiexec T1218.010 System Binary Proxy Execution: Regsvr32 T1218.011 System Binary Proxy Execution: Rundll32 T1218.014 System Binary Proxy Execution: MMC T1220 XSL Script Processing T1221 Template Injection T1222 File and Directory Permissions Modification T1497 Virtualization/Sandbox Evasion T1497.001 Virtualization/Sandbox Evasion: System Checks T1497.003 Virtualization/Sandbox Evasion: Time Based Checks T1553.002 Subvert Trust Controls: Code Signing T1562.001 Disable or Modify Tools T1562.004 Impair Defenses: Disable or Modify System Firewall T1564.001 Hidden Artifacts: Hidden Files and Directories T1574 Hijack Execution Flow T1574.013 Hijack Execution Flow: KernelCallbackTable T1620 Reflective DLL Injection T1622 Debugger Evasion T1003 OS Credential Dumping T1003.003 OS Credential Dumping: NTDS T1056 Input Capture T1056.001 Input Capture: Keylogging T1555 Credentials from Password Stores T1557.001 Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning T1010 Application Window Discovery T1012 Query Registry T1016 System Network Configuration Discovery T1033 System Owner/User Discovery T1046 Network Service Discovery T1049 System Network Connections Discovery T1057 Process Discovery T1083 File and Directory Discovery T1087.002 Account Discovery: Domain Account T1119 Automated Collection T1120 Peripheral Device Discovery T1124 Time Discovery T1482 Domain Trust Discovery T1614.001 System Location Discovery: System Language Discovery T1021 Remote Services T1021.001 Remote Services: Remote Desktop Protocol T1021.004 Remote Services: SSH T1534 Internal Spearphishing T1005 Data from Local System T1074.001 Data Staged: Local Data Staging T1560 Archive Collected Data T1560.002 Archive Collected Data: Archive via Library T1560.003 Archive Collected Data: Archive via Custom Method T1048.003 Exfiltration Over Alternative Protocol: Unencrypted Non-C2 Protocol T1052.001 Exfiltration Over Physical Medium: Exfiltration over USB T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage T1001.003 Data Obfuscation: Protocol or Service Impersonation T1008 Fallback Channels T1071.001 Application Layer Protocol: Web Protocols T1090 Proxy T1090.001 Proxy: Internal Proxy T1090.002 Proxy: External Proxy T1095 Non-Application Layer Protocol T1102 Web Service T1102.002 Web Service: Bidirectional Communication T1104 Multi-Stage Channels T1105 Ingress Tool Transfer T1132.001 Data Encoding: Standard Encoding T1219.002 Remote Access Software: Remote Desktop Software T1571 Non-Standard Port T1573 Encrypted Channel T1573.001 Encrypted Channel: Symmetric Cryptography T1485 Data Destruction T1489 Service Stop T1491.001 Defacement: Internal Defacement T1529 System Shutdown/Reboot T1561.001 Disk Wipe: Disk Content Wipe T1561.002 Disk Wipe: Disk Structure Wipe T1583.001 Acquire Infrastructure: Domains T1583.004 Acquire Infrastructure: Server T1583.006 Acquire Infrastructure: Web Services T1584.001 Compromise Infrastructure: Domains T1584.004 Compromise Infrastructure: Server T1585.001 Establish Accounts: Social Media Accounts T1585.002 Establish Accounts: Email Accounts T1587.001 Develop Capabilities: Malware T1587.002 Develop Capabilities: Code Signing Certificates T1588.002 Obtain Capabilities: Tool T1588.003 Obtain Capabilities: Code Signing Certificates T1588.004 Obtain Capabilities: Digital Certificates T1608.001 Stage Capabilities: Upload Malware T1608.002 Stage Capabilities: Upload Tool T1589.002 Gather Victim Identity Information: Email Addresses T1591 Gather Victim Org Information T1591.004 Gather Victim Org Information: Identify Roles T1593.001 Search Open Websites/Domains: Social Media

Reporting

Research mentioning SafePay

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.