Ransomware family
SafePay Ransomware Decryption & Data Recovery
- Active
- High
- No public decryptor
SafePay emerged in late 2024 and rose sharply through 2025-2026 as a closed, non-RaaS crew. Marked by the .safepay extension and readme_safepay.txt note, it enters mainly through valid credentials on VPN gateways and has passed 500 claimed victims. No public decryptor exists.
- First seen
- 2024-09
- File extensions
- .safepay
- Ransom notes
- readme_safepay.txt
- Affected platforms
- Windows
Family profile
- File extensions
- .safepay
- Ransom notes
- readme_safepay.txt
- Contact patterns
- Tor (.onion) negotiation portal + per-victim ID
- SafePay leak site on Tor
- Email bombing and phone calls impersonating IT support (pressure and initial access)
- Aliases / versions
- SafePay Ransomware、SafePay Team、LockBit 3.0 代码衍生变种
- First seen
- 2024-09
- Status
- Active
- Threat level
- High
- Affected platforms
- Windows
- Tags
- Active
- Leak-site regular
- Double extortion
- RDP brute force
- Exploits vulnerabilities
- Phishing
No free public SafePay decryptor exists. The encryptor uses ChaCha20 with a unique symmetric key per file protected by an embedded asymmetric key, and no exploitable implementation flaw has been published. SafePay's code overlaps heavily with the leaked LockBit 3.0 (LockBit Black) and also contains fragments resembling ALPHV/BlackCat and INC Ransom, but shared ancestry brings no universal decryption - key systems are independent per variant. Recovery relies on backups and snapshots, structural repair, unencrypted duplicates and carving.
Latest activity
Leak-site trackers show SafePay still posting at pace: about 560 cumulative claimed victims, 13 in the past 30 days, the newest clustered in Spain, Italy, Portugal, Austria, Argentina and the Philippines. Still no decryptor.
SourcesSafePay's leak site claimed Air Liquide's South Korean industrial arm (industry.airliquide.kr), an unusual Asia-Pacific large-manufacturing target, showing victimology spreading well beyond the US and Germany.
SourcesIngram Micro notified 42,000+ people over the July 2025 SafePay attack: stolen files included employee and job-applicant names, dates of birth, SSNs, driver's licence and passport numbers. Data risk outlives the outage.
Sources
Overview
SafePay was first observed in September-October 2024 and launched its leak site that November. Unlike mainstream ransomware-as-a-service, it is a closed operation: no affiliate recruitment, no encryptor rental, with the same core team handling access, deployment and negotiation. That structure gives it highly consistent tradecraft and a fast tempo - multiple analyses note SafePay completing the path from intrusion to encryption within hours.
Its growth rate stands out most. Through 2025 SafePay claimed more than 270 victims, peaking at 73 in a single month. By September 2026 its leak site listed roughly 560 claimed victims, with 13 added in the preceding 30 days. Victims still cluster in the United States (~212) and Germany (~126) but now extend to Spain, Italy, Portugal, Austria, Argentina, the Philippines and South Korea, across manufacturing, healthcare, construction, education, research, government and IT services, mostly mid-size businesses and groups.
The defining incident was the July 2025 attack on global IT distributor Ingram Micro: internal systems went down broadly, ordering platforms and distribution operations were affected worldwide, and public reporting traced the entry point to its GlobalProtect VPN gateway. That case also highlights SafePay's preference for MSPs, IT distributors and service providers - one breach reaches a long chain of downstream customers.
Technically, SafePay's code overlaps heavily with the LockBit 3.0 (LockBit Black) build leaked in 2022, with fragments resembling ALPHV/BlackCat and INC Ransom, making it a classically assembled payload. The lesson for Chinese enterprises is direct: SafePay's main entry is valid credentials and password spraying against VPN gateways, and SSL VPN deployments in China commonly share exactly that exposure - weak passwords, MFA not enabled, and departed employees' accounts left active. No public report confirms a targeted SafePay campaign against mainland China organisations.
How to identify it
Extension. .safepay is appended to encrypted files.
Ransom note. readme_safepay.txt is dropped in each encrypted directory. The English text carries a victim-specific ID and a Tor negotiation portal address and states that data has been encrypted and exfiltrated.
Intrusion and deployment indicators.
- Successful VPN gateway logins (GlobalProtect-class SSL VPN, for example) from unfamiliar regions or at odd hours, or a success following heavy password spraying failures.
- Endpoint protection disabled or uninstalled and security services stopped.
- Volume shadow copies deleted and logs cleared.
- In some cases encryption executed through safe mode or a specific boot configuration to evade protection.
- Before exfiltration, WinRAR staging and FileZilla transfers, and abuse of cloud sync channels such as OneDrive so the outbound traffic resembles normal business activity.
Pressure tactics. SafePay pairs email bombing - flooding a mailbox with junk in a short window - with phone calls impersonating IT support, used both to socially engineer access and to apply pressure after encryption. An IT team suddenly receiving mass junk mail while fielding "IT support" calls should treat it as a high-risk signal.
Attribution note. Because the code overlaps heavily with LockBit 3.0, behaviour alone is easy to confuse with LockBit-lineage payloads; accurate identification requires comparing encrypted-file structure and binary fingerprints.
Infection vectors
SafePay's access is unusually concentrated - nearly every public case points to the same category of entry:
- Valid credentials on VPN gateways. Accounts bought on dark-web markets, harvested from infostealer logs or obtained by password spraying are used to log straight into the network over VPN. This is its primary vector, and the Ingram Micro incident was reported as entering via the VPN gateway.
- Password spraying and brute force. Aimed at remote entry points without MFA or login rate limiting.
- VPN and edge device vulnerabilities. Exploitation of unpatched remote access appliances.
- Social engineering. Email bombing combined with phone calls impersonating IT support to get staff to install a remote management tool that admits the attacker.
- Lateral movement. Valid credentials used over RDP and administrative channels toward file servers, database servers, the virtualisation platform and backup systems.
- Defence evasion. Endpoint protection disabled, security services stopped, shadow copies deleted and logs cleared.
- Exfiltration. WinRAR staging with FileZilla transfer, or cloud sync channels such as OneDrive, making outbound traffic hard to distinguish from normal activity.
- Rapid deployment. Because one team runs the whole chain, the window from entry to full encryption is often very short, leaving defenders little reaction time.
For Chinese organisations the three highest-yield defences are: enforce MFA on VPN, promptly remove departed and dormant accounts, and alert on geographic and time anomalies in VPN logins.
Encryption behavior
Algorithms. SafePay encrypts content with ChaCha20, generating a unique symmetric key per file protected by an asymmetric key embedded in the encryptor. Without the operators' private key nothing can be reversed, and public analysis reports no exploitable flaw.
Code lineage. Heavy overlap with the LockBit 3.0 (LockBit Black) code leaked in 2022, plus fragments resembling ALPHV/BlackCat and INC Ransom. Shared code does not mean shared keys - historical LockBit decryption approaches do not apply to SafePay.
Recovery inhibition. Volume shadow copies deleted, security and backup services stopped and event logs cleared, with some cases executing encryption after a safe-mode boot to evade endpoint protection.
Virtualisation scope. Public analysis as of May 2025 found no confirmed standalone VMware ESXi encryptor; the encryptor is a Windows build. That does not make virtualised environments safe: virtual machine files stored on an encrypted Windows or Hyper-V host, or on reachable shares and storage, are encrypted alongside everything else, with business impact comparable to an ESXi locker. Scope the impact from the actual samples and environment rather than relaxing hypervisor checks because no ESXi build exists.
Double extortion. Data is exfiltrated before encryption and published on the leak site if unpaid, reinforced by email bombing and phone pressure.
Assess before you act
Recoverability assessment
No public decryptor exists for SafePay and decryption is not technically viable. We do not pay ransoms and do not negotiate.
1) Backups, snapshots and shadow copies (first and usually most effective). SafePay deletes shadow copies and stops backup services, but its attack window is short and its focus is Windows domain assets, so storage array and NAS volume snapshots, backup appliances with independent credentials, offline tape, offsite copies and cloud version history survive comparatively often. Each must be verified by actual mount, not by backup job status.
2) Structural repair of databases and large files (depends on the encryption pattern). For SQL Server (MDF/LDF), Oracle (DBF), MySQL (ibd) and Hyper-V virtual disks (vhdx), measure the encrypted coverage first. Where data regions remain untouched, page-level extraction and logical rebuilds with transaction log roll-forward apply; virtual disks can have metadata repaired and then be mounted for inner file extraction.
3) Unencrypted duplicates and log replay. File-server previous versions and recycle bins, endpoint caches, reporting and BI staging databases, ERP and MES archive exports, mail system copies, and cloud sync history are all viable sources - though because SafePay also abuses cloud sync, check whether version history was overwritten.
4) Low-level carving. Where the encryptor wrote new files and deleted originals, intact content may survive in unallocated space and can be carved - provided writes stop immediately on discovery and no reinstall or storage rebuild is performed.
5) A specific note for service providers and supply chains. SafePay favours IT distributors and service providers. If your organisation was caught through an upstream provider, recovery must be accompanied by an assessment of whether their remote management channel was used for deployment, whether your credentials on their platform need full rotation, and whether data exchange interfaces between you should be suspended.
For SafePay data recovery we measure first and then state a bounded scope. We do not promise "100% decryption" or guaranteed recovery.
Our response plan
Hit by SafePay ransomware? What to do
Containment and forensic preservation
Isolate affected hosts immediately and disable every suspicious account on the VPN gateway while revoking all active VPN sessions - this is SafePay's primary entry point and a password change alone does not terminate an established session. Disconnect backup media and network shares. Do not reboot or reinstall. Image domain controllers, file servers, database servers and backup servers, and export VPN gateway logs, Windows security logs, outbound firewall records and cloud sync audit logs such as OneDrive, retaining three to five .safepay files and readme_safepay.txt.
Family identification and encryption analysis
Confirm the family from the .safepay extension, readme_safepay.txt format and encrypted-file structure, and distinguish it from code-related LockBit 3.0 variants - behaviour is similar but key systems are independent, and a misattribution sends recovery in the wrong direction. Measure the encrypted coverage of database files and virtual disks and map intact regions, and establish where VM files actually live (Windows host, Hyper-V or shared storage) to scope the virtualisation impact.
Recoverability assessment and plan sign-off
Check backups in layers - appliances and offline media authenticating outside the domain, then storage and NAS volume snapshots, then cloud version history, then domain-joined backup systems - verifying every one by actual mount. Run sample repairs on core databases and key VMs to quantify recoverable volume, and scope the exfiltration from outbound firewall records and cloud sync logs. Deliver a written assessment covering recovery path, expected scope, timeline and business priority per system, then execute after sign-off.
Recovery execution
Work on images in a clean environment with originals read-only. Restore identity and network infrastructure first, then core databases such as finance, ERP and MES, then file and mail systems. Databases go through page-level extraction plus transaction log roll-forward; Hyper-V virtual disks have metadata repaired and are mounted for extraction; file data is restored in batches by business directory, supplemented by deleted-file extraction. After each batch run hash verification, application open tests and business reconciliation into a traceable manifest.
Attribution, hardening and handover
Focus the reconstruction on the VPN side: which account was used for the first login, where the credentials leaked from (password spraying, infostealer or dark-web purchase), whether staff were socially engineered by phone into installing remote tooling, and the timing and volume of exfiltration. Hardening: enforce MFA on VPN with concurrency and source restrictions, remove departed and dormant accounts, alert on geographic and time anomalies at login, patch VPN and edge devices promptly, enable tamper protection on endpoint security and prevent ordinary users from stopping security services, and rebuild backups around out-of-domain authentication, immutable copies and offline media. Where a service provider supply chain is involved, investigate the remote management channel jointly with the upstream party. Close with an incident report, exfiltration conclusion and handover checklist.
Risk warning
What not to do
- Do not assume resetting VPN passwords closes the door. All active VPN sessions must also be revoked and MFA enabled, or an established session remains usable.
- Do not reinstall systems or rebuild storage volumes. With no decryptor available, low-level carving and file structure repair are often the only remaining technical paths, and a reinstall erases them at a stroke.
- Do not use domain credentials to connect to backup systems just to check whether they survived; backups are one of SafePay's lateral movement targets and this can expose the surviving copies.
- Do not trust callers claiming to be IT support who ask you to install a remote management tool - SafePay pairs email bombing with phone impersonation, and such a call may itself be the intrusion.
- Do not skip hypervisor investigation because SafePay has no confirmed ESXi build. Virtual machine files on an encrypted Windows or Hyper-V host, or on shared storage, are encrypted all the same.
- Do not pay or open contact through the portal; data left before encryption, and payment guarantees neither successful decryption nor that the data will not be reused or resold.
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related scenarios
ESXi / Hyper-V Virtualization Encrypted by Ransomware
Hypervisor-level encryption causes the widest blast radius of any ransomware event: dozens of production VMs go dark within an hour or two. This page covers what Linux ESXi encryptors actually do — shut down guests, encrypt vmdk, delete snapshots — the recovery value of flat disk files, and how Hyper-V and Proxmox cases differ.
Domain Controller Compromise and Estate-Wide Encryption
A compromised domain controller hands the attacker a legitimate administrator identity, allowing an encryptor to be pushed to every host at once through Group Policy or remote execution. This page covers how such incidents present, the correct order for Active Directory recovery, and how to decide between cleanup and full rebuild.
File Servers and NAS Encrypted by Ransomware
When shared folders on a file server or NAS are encrypted, drawings, contracts, archives, quotations and design sources all become unusable at once — and mapped drives spread the impact to every endpoint. This page covers how to gauge spread, what shadow copies and snapshots realistically offer, and how to sequence recovery by business value.
Backups Deleted or Destroyed
Modern ransomware follows a fixed sequence: destroy the backups, then encrypt the data — deleting shadow copies, encrypting repositories, disabling jobs, and exploiting backup software flaws to steal credentials. This page covers what can still be inventoried once backups fail, why replication propagates encrypted files off-site, and what offline and immutable copies are really worth.
Related industries
Manufacturing Ransomware Response and Recovery
Ransomware in manufacturing hits information systems and production cadence at the same time: with ERP down there are no orders, with MES down there is no schedule, and an encrypted drawing library takes the process documentation for an entire product line with it. This page covers the asset profile, recovery priorities and targeted defences.
Construction and Real Estate Ransomware Response
In construction and real estate the core assets are drawings, models and project documentation — typically scattered across project-site NAS units, shared drives and personal computers with no unified backup. This page covers the sector's threat profile, recovery of drawings and BIM models, and defences for dispersed, multi-project environments.
Logistics and Supply Chain Ransomware Response
Logistics is acutely time-sensitive: when TMS, WMS, dispatch and sorting systems stop, goods pile up in warehouses and on routes immediately, and the effect propagates up and down the supply chain. This page covers the sector's threat profile, a recovery order built around goods movement, and hardening for EDI-interconnected environments.
Similar families
- Some versions decryptable
LockBit
LockBit is one of the largest ransomware-as-a-service operations in the world. Despite the 2024 law-enforcement takedown it returned as LockBit 5.0, with working Windows, Linux and VMware ESXi payloads, and it remains one of the most frequently seen families in China.
- No public decryptor
INC Ransom
INC Ransom emerged in 2023 and has passed 800 claimed victims by 2026, making it a top-tier RaaS operation. Marked by the .INC extension and INC-README notes, it exploits Citrix and SonicWall edge flaws and ships an ESXi encryptor. No public decryptor exists.
- No public decryptor
BlackCat
BlackCat (ALPHV) was the first major Rust-based ransomware-as-a-service operation, active from November 2021. It seized accounts through help-desk social engineering, encrypted ESXi and Windows estates under double extortion, and shut down in a March 2024 exit scam after keeping the Change Healthcare ransom — its key infrastructure no longer exists.
FAQ
SafePay Frequently asked questions
Can .safepay files be decrypted?
There is no public decryptor. SafePay encrypts with ChaCha20 using a per-file key protected by an embedded asymmetric key, with no published implementation flaw. Although its code overlaps heavily with the leaked LockBit 3.0, key systems are independent and historical LockBit approaches do not apply. Real SafePay data recovery runs through backups and snapshots, structural repair of databases and virtual disks, unencrypted duplicates and low-level extraction from unallocated space.
How did they get in - was our VPN the problem?
Most likely yes. Public analysis consistently identifies valid credentials on VPN gateways as SafePay's primary entry: accounts bought on dark-web markets, taken from infostealer logs, or obtained by password spraying against entry points without MFA. The July 2025 Ingram Micro incident was reported as entering through its GlobalProtect VPN gateway. Investigation should focus on successful VPN logins from unusual regions or hours, successes following heavy failures, and activity on departed or dormant accounts. All active sessions must be revoked during response - changing passwords alone achieves nothing.
Our mailbox was flooded with junk and we got an IT support call - is that related?
Highly suspicious and should be handled as a security incident immediately. SafePay pairs email bombing with phone calls impersonating IT support: mass junk mail creates confusion, then a call offering to fix the mail problem persuades staff to install a remote management tool, handing over access directly. The correct response is to install nothing during the call, provide no credentials or verification codes, hang up and verify the caller through known internal channels, and report to the security team at once.
SafePay has no ESXi encryptor - are our virtual machines safe?
No. Public analysis as of May 2025 found no confirmed standalone VMware ESXi encryptor and the payload is a Windows build. But virtual machine files stored on an encrypted Windows host, a Hyper-V server, or reachable shares and storage are encrypted all the same, with business impact no different from an ESXi locker. Response should establish where VM files actually live and scope the impact from the real environment rather than skipping hypervisor checks because no ESXi build exists.
We were affected through our IT provider - what beyond restoring data?
SafePay clearly favours IT distributors and service providers because one intrusion reaches an entire downstream chain. Alongside data recovery, do four things: suspend the upstream provider's remote management channel and confirm whether it was used for deployment; fully rotate your accounts, keys and API credentials on their platform; review data exchange interfaces and shared accounts between the organisations for cross-tenant lateral paths; and establish the responsibility boundary and notification obligations for the exfiltrated data, handling the contractual and compliance dimensions in parallel.
Sources
- SafePay Ransomware: How a Non-RaaS Group Executes Rapid Fire Attacks — Bitdefender
- SafePay: The new kid on the block — DCSO CyTec
- SafePay Ransomware: How It Works & How to Stop It — Huntress
- Exfiltration in Plain Sight: SafePay's OneDrive Play — Sygnia
- SafePay Ransomware: An Emerging Threat in 2025 — Check Point
External links are provided for reference only. The content is published by third parties and does not represent our position.
Updated