🚀 CloudSEK featured in the 2026 Frost Radar™!
Read more
SafePay ransomware is a double-extortion ransomware operation that steals data, encrypts files with a .safepay extension, and threatens to publish the stolen data on its leak site.
A closed core team runs every stage of the operation, with no ransomware-as-a-service (RaaS) affiliates. That team gains access, moves through the network, steals data, and deploys an encryptor built on leaked LockBit Black code.
Valid VPN and RDP credentials open most SafePay intrusions, followed by standard administration tools that blend into normal activity. Identity controls and behavioral detection decide whether an attack stops at the login or ends in encryption.
SafePay's profile combines a centralized operating model, LockBit-derived malware, and credential-based intrusions.
SafePay gains initial access mainly through valid remote access credentials, supported by weak passwords, social engineering, and purchased access.

In both intrusions Huntress investigated, SafePay operators signed in through the victim's VPN gateway with valid credentials, then connected to servers over RDP.
The operators did not need to create new accounts or install persistence because the stolen logins kept working.
Infostealer malware harvests the kind of VPN and browser credentials that open this access path. Ransomware.live, using Hudson Rock data, found infostealer infections linked to 20.5% of SafePay victims with a known domain, a pattern that makes leaked credential monitoring a frontline control against this group.
NCC Group published an incident analysis that traced a SafePay intrusion back to weak passwords. Accounts protected only by a password convert a single guessed or reused credential into full network entry.
Barracuda researchers described SafePay intrusions that flood employee inboxes with spam, then contact those employees through Microsoft Teams while posing as internal IT support.
The caller offers to fix the spam problem and persuades the employee to grant remote access through a tool such as Microsoft Quick Assist.
Help desk impersonation mirrors earlier Black Basta campaigns and turns the help desk itself into an attack vector, one of several social engineering attacks that bypass technical controls entirely.
SafePay operators break in themselves and buy network access from initial access brokers. Reporting links the group to exploited vulnerabilities and security misconfigurations on internet-facing systems, although stolen credentials remain the most consistent entry point.
A SafePay attack moves from a valid login to share discovery, data theft, recovery sabotage, and network-wide encryption. Here are the main attack stages of the SafePay ransomware attack:
The pace of SafePay intrusions varies between documented incidents and victims. Other vendors report SafePay moving from initial access to encryption within 24 hours, while the Huntress case above spanned several days of staging before a fast final deployment.
The SafePay encryptor is a Windows DLL, observed as locker.dll, that runs through regsvr32.exe and reuses large parts of the leaked LockBit Black codebase.
The encryptor inherits LockBit Black's password argument, which operators supply at launch. Huntress documented 8 command-line flags:
Before encryption, SafePay terminates database, email, and office processes, such as SQL Server, Oracle, Outlook, and Word, so their files unlock. It stops services tied to shadow copies and backups, including VSS, Veeam, and Sophos components.
The encryptor enables SeDebugPrivilege, duplicates access tokens for privileged threads, and hides worker threads from debuggers. Bitdefender reports that it encrypts files with ChaCha20, using a unique symmetric key per file protected by a key embedded in the ransomware.
Early SafePay samples checked the system's default user interface language and stopped if it matched a Cyrillic language. ThreatLocker reported that later samples removed this check.
Code lineage, not confirmed organizational continuity, connects SafePay to LockBit.
The LockBit 3.0 builder leaked in 2022, and several unrelated groups built encryptors from it, so shared code alone does not identify the people behind SafePay.
Detection rules written for LockBit 3.0 command-line patterns catch part of SafePay's execution behavior. Credential-based access and hands-on-keyboard staging still need their own detections.
No, SafePay is not a ransomware-as-a-service group. SafePay states on its leak site that it does not run an affiliate program, and researchers have found no affiliate recruitment posts from the group on cybercrime forums.
In a ransomware-as-a-service model, developers rent malware to affiliates who carry out their own intrusions, which produces varied tactics across victims of groups such as Qilin. SafePay's single team produces a consistent playbook, and some researchers assess that the group recruited experienced operators from collapsed operations such as Conti and Black Basta.
SafePay targets small and mid-sized businesses, managed service providers, and IT distributors, with the heaviest activity in the United States and Germany. Ransomware.live listed 569 SafePay victims across 47 countries as of September 17, 2026.
Leak-site counts undercount real activity, because victims who pay are not listed. Ransom demands reportedly fall between 1% and 3% of a victim's annual revenue, according to Infosecurity Magazine reporting.
MSP and distributor victims carry outsized risk for their downstream customers. One compromised provider exposes the downstream clients that trust its remote access, the same dynamic behind a supply chain attack.
Ingram Micro, one of the world's largest IT distributors, suffered a global outage starting July 3, 2025, that took down its website, online ordering, the Xvantage distribution platform, and the Impulse license provisioning platform.
Sources told BleepingComputer that SafePay was behind the Ingram Micro attack and that access likely came through the company's GlobalProtect VPN using compromised credentials, not a flaw in the VPN itself. SafePay added Ingram Micro to its leak site later that month and threatened to publish 3.5 TB of data.
SafePay attacked Microlise, a UK provider of fleet tracking and transport management technology, in October 2024.
The incident disrupted Microlise customers, including DHL deliveries and security systems on UK Ministry of Justice prisoner transport vans, and SafePay claimed to have stolen 1.2 TB of data.
SafePay IOCs include file artifacts, execution patterns, tool traces, and attacker infrastructure. Hashes and hostnames change between campaigns, so behavioral indicators outlast static ones.
SafePay activity maps to more than a dozen MITRE ATT&CK techniques across initial access, defense evasion, exfiltration, and impact. The table below maps publicly reported behavior to the MITRE ATT&CK framework.
To detect SafePay ransomware, security teams watch for its staging behavior between the first login and encryption, because that window gives defenders the most time to act.
Each signal above has a legitimate explanation when viewed alone. Defender tampering, share enumeration, and bulk archiving from the same account within days form a pattern that justifies containment without waiting for encryption.
Preventing SafePay ransomware starts with removing the credential access paths the group relies on, then limiting what an intruder reaches.
Responding to a SafePay attack requires containing the operator's access before restoring anything, because the group enters with valid credentials that survive a system rebuild.
Paying SafePay does not guarantee a working decryptor or deletion of stolen data. Payments to sanctioned entities create legal exposure in the United States and other jurisdictions, so any payment decision involves legal counsel and law enforcement guidance.
Security teams need to know when SafePay starts hitting their sector, region, or suppliers, before a listing appears with their own name.
CloudSEK Threat Intelligence delivers ransomware intelligence with live alerts on global ransomware activity, impact assessments, and visibility into the sectors and victims being targeted.
That context shows when a peer, vendor, or MSP appears on a leak site and which access methods the group is using. Teams then check their own VPN logs, credential exposure, and third-party access for the same entry points.
Is SafePay ransomware still active?
Yes, SafePay Ransomware remains an active and emerging threat.
Is SafePay ransomware related to Bitdefender Safepay?
No. Bitdefender Safepay is a secure browser feature in Bitdefender products, while SafePay ransomware is an unrelated criminal group that shares the name.
Where can victims check for a SafePay decryptor?
Victims can check the No More Ransom project, which hosts free decryptors from law enforcement and security companies, before engaging with the attackers.
Can antivirus stop SafePay ransomware?
No, not reliably. In one Huntress investigation, Microsoft Defender detected the SafePay process but failed to stop it, and encryption continued.
Does paying SafePay guarantee stolen data is deleted?
No. Victims have no way to verify deletion, and double-extortion groups retain stolen copies regardless of what they promise.
Is it legal to pay a SafePay ransom?
It varies by jurisdiction. Payments to sanctioned individuals or groups violate US sanctions rules, and Australia requires businesses to report ransom payments.
