SafePay is a privately operated ransomware family and associated extortion operation that emerged in late 2024 and rapidly became one of the more active ransomware brands observed through 2025 and into 2026. It is characterized as a centralized, non-RaaS operation that conducts double extortion by stealing victim data and then encrypting systems, using leak-site publication and direct pressure to coerce payment. Reported victimology shows broad international targeting, with repeated observations of concentration in Germany and substantial activity in the United States, as well as recurring impact on healthcare, manufacturing, managed service providers, and small-to-midsize businesses.
Intrusion reporting links SafePay to credential-based access against remote access infrastructure, including password spraying against VPN gateways, followed by a dwell period, privilege escalation to domain-wide administrative access, network share discovery, backup targeting, data collection, exfiltration, and encryption. Operators have been observed deleting shadow copies and encrypting backup-related assets to hinder recovery. In at least one investigated case, activity occurred inside guest virtual machines rather than directly at the hypervisor layer, and analysts assessed the group likely lacked an ESXi-compatible encryptor at that time.
The SafePay encryptor is a custom Windows ransomware written in C. Reported technical characteristics include asynchronous file encryption using Overlapped I/O, support for partial encryption, use of AES-CBC when AES-NI is available and ChaCha20 otherwise, and Curve25519 to protect per-file key material. The malware has been described as influenced by established ransomware design patterns while likely developed independently rather than directly derived from a known family.
SafePay has been associated with numerous publicly claimed intrusions and data-theft incidents, including attacks affecting healthcare entities, government service providers, distributors, and industrial or manufacturing-related organizations. The operation has been repeatedly described as financially motivated and not politically aligned. Its tradecraft and malware design indicate a capable but not top-tier actor, with intermediate sophistication and effective extortion operations despite reliance on largely conventional intrusion methods.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The SafePay ransomware group is a relatively new group, first appearing on our radar in November 2024. The group follows a double-extortion scheme, both exfiltrating data and encrypting it on victim machines using their own SafePay ransomware.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
It took the SafePay ransomware group 26 days from initial access to obtain Domain Admin privileges
T1078.002 - Valid Accounts: Domain Accounts. The Threat Actor was able to gain access to a local account through a simple misconfiguration of the firewall. Once inside, the Threat Actor was able to escalate to a domain administrator account not covered by MFA at the time of the attack.
It took the SafePay ransomware group 26 days from initial access to obtain Domain Admin privileges
T1078.002 - Valid Accounts: Domain Accounts. The Threat Actor was able to gain access to a local account through a simple misconfiguration of the firewall. Once inside, the Threat Actor was able to escalate to a domain administrator account not covered by MFA at the time of the attack.
It took the SafePay ransomware group 26 days from initial access to obtain Domain Admin privileges
T1078.002 - Valid Accounts: Domain Accounts. The Threat Actor was able to gain access to a local account through a simple misconfiguration of the firewall. Once inside, the Threat Actor was able to escalate to a domain administrator account not covered by MFA at the time of the attack.
It took the SafePay ransomware group 26 days from initial access to obtain Domain Admin privileges
T1078.002 - Valid Accounts: Domain Accounts. The Threat Actor was able to gain access to a local account through a simple misconfiguration of the firewall. Once inside, the Threat Actor was able to escalate to a domain administrator account not covered by MFA at the time of the attack.
There number of ransomware attacks against organizations across Europe has significantly increased during the past year... They found that ransomware attacks rose 55.1% year-over-year in the first four months of 2026 and reached an average of 171 incidents per month.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
45 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware operation listed among active groups impacting industrial organizations in Q2 2026.
A ransomware family active against healthcare victims in 2025.
Ransomware used in the January 2025 attack against Marlboro-Chesterfield Pathology that led to unauthorized network access and compromise of patient and personal data.
Ransomware family noted as the third most common in the report, with activity appearing concentrated in Germany and likely aimed at specific organizations there.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.