Overview

Platforms: Windows
Variants: —
Extensions: .safepay
ATT&CK software: PsExec (S0029) · Rclone (S1040)
Initial access: External Remote Services
Top countries: US · DE · GB · CA · IT
Observed sectors: Manufacturing · Professional Services · Retail & E-Commerce · Technology · Healthcare
Tracked victims: 569

Attribution

GOLD LEAPFROG VERIFIED
Vendor tracking name
Sophos / Secureworks threat intelligence uses GOLD LEAPFROG to track activity associated with SafePay ransomware deployment.

Affiliates

No affiliate information available.

Activity

Recent Observations

Continued SafePay victim claims
September 2026
Leak-site activity
SafePay continued publishing new victim claims during September 2026, including a new listing observed on September 13.
SafePay remains a leading ransomware operation
January 2026
Threat landscape
Sophos identified SafePay, tracked as GOLD LEAPFROG, among the most frequently observed ransomware brands in incident-response activity.
Ingram Micro ransomware attack
July 2025
Major incident
A ransomware incident disrupted Ingram Micro systems globally. SafePay was linked to the intrusion through ransom notes and later claimed the organization on its leak site.
SafePay becomes a leading operation
June 2025
Ransomware activity
Bitdefender reported 73 SafePay victim claims during June 2025, placing it among the most active ransomware operations at the time.

TTPs

ATT&CK coverage: 9 techniques · 7 tactics
T1133 External Remote Services
VERIFIED
Persistence / Initial Access
SafePay actors have used compromised VPN credentials to obtain access to victim environments.
T1021.001 Remote Desktop Protocol
VERIFIED
Lateral Movement
SafePay operators have used RDP connections for ransomware delivery and hands-on-keyboard access inside compromised networks.
T1548.002 Bypass User Account Control
VERIFIED
Privilege Escalation / Defense Evasion
SafePay contains functionality to abuse the CMSTPLUA COM interface for UAC bypass.
Show more TTPs (6)
T1135 Network Share Discovery
VERIFIED
Discovery
SafePay operators have used ShareFinder to enumerate network shares across victim domains.
T1560.001 Archive via Utility
VERIFIED
Collection
SafePay intrusions have used WinRAR to package collected victim files before exfiltration.
T1562.001 Impair Defenses
VERIFIED
Defense Evasion
SafePay operators disable endpoint protection, including Windows Defender, before ransomware deployment.
T1070.001 Clear Windows Event Logs
VERIFIED
Defense Evasion
SafePay activity includes clearing event logs to reduce forensic visibility.
T1490 Inhibit System Recovery
VERIFIED
Impact
SafePay deletes Windows volume shadow copies to interfere with recovery.
T1486 Data Encrypted for Impact
VERIFIED
Impact
SafePay encrypts victim files using ChaCha20 or AES-CBC depending on system capabilities and supports configurable partial encryption.

Victims

Ingram Micro CONFIRMED
July 2025 US Technology
Technology organization in US.

CVEs

No CVE associations available.

Infrastructure

SafePay leak site
SafePay operates Tor-hosted leak infrastructure used to publish victim claims and stolen information as part of its double-extortion model.
Centralized operational infrastructure
Public technical reporting indicates that SafePay centrally manages intrusion activity, ransomware deployment, infrastructure and victim negotiations rather than operating a conventional public affiliate program.
Data exfiltration tooling
SafePay intrusions have used WinRAR for staging and FileZilla for transferring stolen data before ransomware deployment.

Timeline

2026-09
Continued active operation
SafePay continued publishing new victim claims in September 2026, confirming continued operational activity.
2026-01
SafePay remains prominent
SafePay remained among the ransomware brands most frequently encountered in incident-response investigations.
2025-07
Ingram Micro attack
A ransomware attack disrupted Ingram Micro operations globally; SafePay was linked through ransomware artifacts and subsequently claimed the incident.
Show more events (3)
2025-06
SafePay becomes a leading operation
SafePay reached one of the highest ransomware victim-claim volumes observed during mid-2025.
2024-11
Public leak-site activity begins
SafePay began establishing a visible victim publication record through its data leak infrastructure.
2024-09
SafePay emerges
SafePay ransomware activity began appearing in public threat intelligence reporting during late 2024.

Sources