SafePay is a Windows ransomware family used by the SafePay cyber-extortion operation, active since late 2024. The operation employs double extortion, stealing victim data before encrypting systems and threatening publication through its leak site. SafePay has disproportionately targeted organizations in Germany and the United States, with reported victims spanning manufacturing, healthcare, technology, and other business sectors. The operators characterize the operation as centralized rather than ransomware-as-a-service.
Observed intrusions have obtained access through password spraying against VPN services and exploitation of exposed FortiGate SSL VPN infrastructure, particularly where privileged accounts lacked multifactor authentication. Operators conduct network and share discovery, search for credentials, escalate to domain-administrator privileges, move laterally through RDP, administrative shares, and PowerShell, and target backup and virtualization infrastructure. Stolen data is staged in compressed archives and has been exfiltrated through both conventional transfer attempts and abuse of the legitimate Microsoft OneDrive synchronization client connected to attacker-controlled cloud tenants.
The SafePay encryptor is a custom C-based Windows payload that supports partial encryption and asynchronous I/O. It uses AES-CBC on systems supporting AES-NI or ChaCha20 otherwise, with Curve25519 protecting per-file key material. Observed payload execution used a malicious DLL loaded through the signed Windows regsvr32 utility, and persistence was established through a Windows Run entry. Operators have deleted Volume Shadow Copies and encrypted backup-related systems to impair recovery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The SafePay ransomware group is a relatively new group, first appearing on our radar in November 2024. The group follows a double-extortion scheme, both exfiltrating data and encrypting it on victim machines using their own SafePay ransomware.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
It took the SafePay ransomware group 26 days from initial access to obtain Domain Admin privileges
T1078.002 - Valid Accounts: Domain Accounts. The Threat Actor was able to gain access to a local account through a simple misconfiguration of the firewall. Once inside, the Threat Actor was able to escalate to a domain administrator account not covered by MFA at the time of the attack.
It took the SafePay ransomware group 26 days from initial access to obtain Domain Admin privileges
T1078.002 - Valid Accounts: Domain Accounts. The Threat Actor was able to gain access to a local account through a simple misconfiguration of the firewall. Once inside, the Threat Actor was able to escalate to a domain administrator account not covered by MFA at the time of the attack.
It took the SafePay ransomware group 26 days from initial access to obtain Domain Admin privileges
T1078.002 - Valid Accounts: Domain Accounts. The Threat Actor was able to gain access to a local account through a simple misconfiguration of the firewall. Once inside, the Threat Actor was able to escalate to a domain administrator account not covered by MFA at the time of the attack.
It took the SafePay ransomware group 26 days from initial access to obtain Domain Admin privileges
T1078.002 - Valid Accounts: Domain Accounts. The Threat Actor was able to gain access to a local account through a simple misconfiguration of the firewall. Once inside, the Threat Actor was able to escalate to a domain administrator account not covered by MFA at the time of the attack.
"gob.pe ... has fallen victim to a ransomware attack conducted by the group safepay."
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
50 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation described as one of Germany's most active groups, accounting for 22% of the country's 2025 attacks.
A double-extortion ransomware operation that steals data before encrypting victim systems. In this incident, it adapted after FTP exfiltration was blocked by using OneDrive synchronization to an attacker-controlled tenant, then deployed a malicious DLL via regsvr32.exe and encrypted more than 60 servers.
Named as one of the five most common ransomware-as-a-service brands in Sophos's ransomware observations.
Ransomware operation included in NCC Group's July activity rankings.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.