Overview
Platforms:
Windows
Variants:
—
Extensions:
.safepay
ATT&CK software:
PsExec (S0029) · Rclone (S1040)
Initial access:
External Remote Services
Top countries:
US · DE · GB · CA · IT
Observed sectors:
Manufacturing · Professional Services · Retail & E-Commerce · Technology · Healthcare
Tracked victims:
569
Attribution
GOLD LEAPFROG
VERIFIED
Vendor tracking name
Sophos / Secureworks threat intelligence uses GOLD LEAPFROG to track activity associated with SafePay ransomware deployment.
Affiliates
No affiliate information available.
Activity
Recent Observations
Continued SafePay victim claims
September 2026
Leak-site activity
SafePay continued publishing new victim claims during September 2026, including a new listing observed on September 13.
SafePay remains a leading ransomware operation
January 2026
Threat landscape
Sophos identified SafePay, tracked as GOLD LEAPFROG, among the most frequently observed ransomware brands in incident-response activity.
Ingram Micro ransomware attack
July 2025
Major incident
A ransomware incident disrupted Ingram Micro systems globally. SafePay was linked to the intrusion through ransom notes and later claimed the organization on its leak site.
SafePay becomes a leading operation
June 2025
Ransomware activity
Bitdefender reported 73 SafePay victim claims during June 2025, placing it among the most active ransomware operations at the time.
TTPs
ATT&CK coverage:
9 techniques
· 7 tactics
T1133
External Remote Services
VERIFIEDPersistence / Initial Access
SafePay actors have used compromised VPN credentials to obtain access to victim environments.
T1021.001
Remote Desktop Protocol
VERIFIEDLateral Movement
SafePay operators have used RDP connections for ransomware delivery and hands-on-keyboard access inside compromised networks.
T1548.002
Bypass User Account Control
VERIFIEDPrivilege Escalation / Defense Evasion
SafePay contains functionality to abuse the CMSTPLUA COM interface for UAC bypass.
Show more TTPs (6)
T1135
Network Share Discovery
VERIFIEDDiscovery
SafePay operators have used ShareFinder to enumerate network shares across victim domains.
T1560.001
Archive via Utility
VERIFIEDCollection
SafePay intrusions have used WinRAR to package collected victim files before exfiltration.
T1562.001
Impair Defenses
VERIFIEDDefense Evasion
SafePay operators disable endpoint protection, including Windows Defender, before ransomware deployment.
T1070.001
Clear Windows Event Logs
VERIFIEDDefense Evasion
SafePay activity includes clearing event logs to reduce forensic visibility.
T1490
Inhibit System Recovery
VERIFIEDImpact
SafePay deletes Windows volume shadow copies to interfere with recovery.
T1486
Data Encrypted for Impact
VERIFIEDImpact
SafePay encrypts victim files using ChaCha20 or AES-CBC depending on system capabilities and supports configurable partial encryption.
Victims
Ingram Micro
CONFIRMED
Technology organization in US.
CVEs
No CVE associations available.
Infrastructure
SafePay leak site
SafePay operates Tor-hosted leak infrastructure used to publish victim claims and stolen information as part of its double-extortion model.
Centralized operational infrastructure
Public technical reporting indicates that SafePay centrally manages intrusion activity, ransomware deployment, infrastructure and victim negotiations rather than operating a conventional public affiliate program.
Data exfiltration tooling
SafePay intrusions have used WinRAR for staging and FileZilla for transferring stolen data before ransomware deployment.
Timeline
2026-09
Continued active operation
SafePay continued publishing new victim claims in September 2026, confirming continued operational activity.
2026-01
SafePay remains prominent
SafePay remained among the ransomware brands most frequently encountered in incident-response investigations.
2025-07
Ingram Micro attack
A ransomware attack disrupted Ingram Micro operations globally; SafePay was linked through ransomware artifacts and subsequently claimed the incident.
Show more events (3)
2025-06
SafePay becomes a leading operation
SafePay reached one of the highest ransomware victim-claim volumes observed during mid-2025.
2024-11
Public leak-site activity begins
SafePay began establishing a visible victim publication record through its data leak infrastructure.
2024-09
SafePay emerges
SafePay ransomware activity began appearing in public threat intelligence reporting during late 2024.
Sources
Ransom:Win32/Safepay.A
Microsoft Security Intelligence
SafePay ransomware: The fast-rising threat targeting MSPs
Acronis Threat Research Unit
Show more sources (11)
SafePay ransomware
Broadcom / Symantec
Cybersecurity Incident
Ingram Micro
SafePay ransomware tracker
Invaders Cybersecurity
SafePay ransomware group profile
Ransomware.live
It's Not Safe To Pay SafePay
Huntress