SafePay is a financially motivated ransomware operation and associated custom ransomware strain that emerged in late 2024 and became one of the more active extortion actors through 2025 and early 2026. The group presents itself as a private, centralized operation rather than a ransomware-as-a-service program. It uses a double-extortion model, stealing victim data and then encrypting systems to pressure payment, with non-paying victims publicly exposed on its leak site. Reported victimology indicates broad cross-sector targeting, with repeated visibility in healthcare and notable activity against managed service providers and small-to-midsize businesses, as well as organizations in North America and Europe, especially the United States and Germany.
Observed intrusions show SafePay relying on conventional but effective human-operated tradecraft rather than highly novel techniques. Documented initial access includes password spraying against VPN infrastructure, followed by a dwell period before privilege escalation, internal discovery, data collection, exfiltration, and rapid encryption. Operators have used publicly available administrative and post-compromise tooling for share enumeration and data staging, searched for and encrypted backup resources, and deleted shadow copies to hinder recovery. In at least one investigated case, the actor obtained domain administrator privileges after a prolonged intrusion and completed collection, exfiltration, and encryption in a compressed final phase. The group has also been reported to directly contact victims by telephone to intensify extortion pressure.
The SafePay ransomware itself is a custom Windows encryptor written in C. Analysis has described asynchronous file encryption using Overlapped I/O, support for partial encryption, and conditional use of AES-CBC or ChaCha20 depending on processor support, with Curve25519 protecting per-file key material. Researchers assessing the malware found design similarities to several established ransomware families but concluded it was likely independently developed rather than a direct derivative. Operational reporting has also suggested that, at least during part of 2025, SafePay lacked a native VMware ESXi encryptor and instead carried out observed encryption activity from within guest virtual machines.
SafePay has been linked to multiple significant extortion incidents, including attacks affecting healthcare entities, government service providers, and large enterprises. Public reporting associates the group with major data theft and disruption events involving organizations such as Conduent and Ingram Micro. Across 2025, SafePay was repeatedly ranked among the more active ransomware brands by victim volume and was consistently identified as a notable threat to the healthcare sector.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The SafePay ransomware group is a relatively new group, first appearing on our radar in November 2024. The group follows a double-extortion scheme, both exfiltrating data and encrypting it on victim machines using their own SafePay ransomware.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
It took the SafePay ransomware group 26 days from initial access to obtain Domain Admin privileges
T1078.002 - Valid Accounts: Domain Accounts. The Threat Actor was able to gain access to a local account through a simple misconfiguration of the firewall. Once inside, the Threat Actor was able to escalate to a domain administrator account not covered by MFA at the time of the attack.
It took the SafePay ransomware group 26 days from initial access to obtain Domain Admin privileges
T1078.002 - Valid Accounts: Domain Accounts. The Threat Actor was able to gain access to a local account through a simple misconfiguration of the firewall. Once inside, the Threat Actor was able to escalate to a domain administrator account not covered by MFA at the time of the attack.
It took the SafePay ransomware group 26 days from initial access to obtain Domain Admin privileges
T1078.002 - Valid Accounts: Domain Accounts. The Threat Actor was able to gain access to a local account through a simple misconfiguration of the firewall. Once inside, the Threat Actor was able to escalate to a domain administrator account not covered by MFA at the time of the attack.
It took the SafePay ransomware group 26 days from initial access to obtain Domain Admin privileges
T1078.002 - Valid Accounts: Domain Accounts. The Threat Actor was able to gain access to a local account through a simple misconfiguration of the firewall. Once inside, the Threat Actor was able to escalate to a domain administrator account not covered by MFA at the time of the attack.
A new report links 148 ransomware attacks to Italian organizations in H1 2026... Two groups dominate the leaderboard, tied at 21 claims apiece: LockBit5 and Qilin.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family active against healthcare victims in 2025.
Ransomware used in the January 2025 attack against Marlboro-Chesterfield Pathology that led to unauthorized network access and compromise of patient and personal data.
A centralized non-RaaS ransomware operation whose activity sharply declined after its data leak site became inactive.
Ransomware family/group associated with data theft and extortion, operating its own leak site and claiming numerous victims across multiple countries. The content states it is not a ransomware-as-a-service operation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.