Sentrix

Actor · Closed · since 2024

SafePay: the closed group that comes in through the VPN

Profile of SafePay, a closed ransomware group that emerged in 2024, gets in through VPN and RDP with valid credentials and encrypts in under twenty-four hours.

Model
Closed group · since 2024-09
Aliases
GOLD LEAPFROG
Ways in
Valid credentials on VPN gateways · RDP with compromised accounts · Known VPN vulnerabilities · Credentials bought on marketplaces
Targets
Windows servers · IT distribution · Telematics and transportation · Organizations in Germany

By Sentrix · Published 2026-09-20

Who they are

SafePay was first identified in September 2024, according to Check Point; Huntress analyzed its first two intrusions observed in customer environments in October 2024. Unlike most brands of the moment, SafePay is not ransomware-as-a-service: Huntress describes a closed group in which the same core team handles access, deployment and extortion, with no affiliates. Sophos tracks the operator as GOLD LEAPFROG in its Threat Intelligence Executive Report, Volume 2025, Number 5.

The binary is nothing original. Huntress notes extensive overlap with the leaked LockBit Black source code, down to shared command-line flags and encryption logic. Encrypted files carry the .safepay extension and the note is named readme_safepay.txt. What matters is the pace: Check Point describes attacks that move from breach to deployment in under twenty-four hours; Huntress measured two to three days from reconnaissance to encryption in its two cases.

Volume followed. Check Point counts 77 publicly claimed victims in the first quarter of 2025 and notes that in Germany, 24% of reported ransomware victims that quarter were linked to SafePay. Sophos's 2026 Active Adversary Report places SafePay among the five brands most encountered in its cases between November 2024 and October 2025, behind Akira and Qilin.

How they get in

One door, or almost: legitimate remote access. Check Point describes valid credentials, most likely purchased on dark web marketplaces, used against a VPN gateway, and does not rule out exploitation of known VPN vulnerabilities. Huntress saw in both of its incidents an RDP login with valid credentials. Sophos cites an early 2025 attack in which GOLD LEAPFROG abused VPN credentials all the way to SafePay deployment.

Then, according to Huntress: share reconnaissance with ShareFinder.ps1, archiving with WinRAR, an exfiltration attempt with FileZilla, then encryption. The Sophos 2026 report recalls that in its cases, 67.32% of root causes were related to compromised identity and that the lack of MFA remained the top contributing weakness, at 59%. SafePay is that statistic made concrete.

What they have done

  • October and November 2024: Microlise. Check Point reports that the UK telematics company disclosed an incident in October 2024 and that SafePay claimed in November to have stolen 1.2 terabytes of data, with an ultimatum of under twenty-four hours.
  • July 2025: Ingram Micro. The Register reports that the attack took place on July 2, 2025, that the distributor detected it a day later and confirmed ransomware was involved, that SafePay claimed to have stolen 3.5 TB of data, and that Ingram Micro notified 42,521 employees and job applicants in a filing with the Maine attorney general's office in January 2026.

What stops them

  1. MFA on VPN and RDP, no exceptions. Every intrusion documented here starts with a valid credential used without a second factor. ISO 27001:2022, 8.5; SOC 2, CC6.1.
  2. No RDP exposed to the internet. Remote access through a VPN with MFA or a bastion host, RDP closed at the perimeter and monitored inside. ISO 27001:2022, 8.20 and 8.21.
  3. VPN login monitoring. Alert on logins from unusual countries or providers, at off-hours, and from accounts that had never used the VPN. SOC 2, CC7.2; ISO 27001:2022, 8.16.
  4. Detection in under a day. With two to three days measured by Huntress and under twenty-four hours according to Check Point, managed detection that responds at night and on weekends is not a luxury. SOC 2, CC7.3; ISO 27001:2022, 5.24.
  5. Blocking of exfiltration tools. WinRAR and FileZilla on a file server, a bulk transfer to an unknown address: these signals can be detected and blocked. ISO 27001:2022, 8.12.
  6. Supplier accounts and third-party access. Every third-party remote access needs its own account, its own MFA and an end date; a shared, permanent VPN credential is exactly what gets resold on the marketplaces described by Check Point. ISO 27001:2022, 5.19 to 5.22; SOC 2, CC9.2.

Sources

Frequently asked questions

How is a closed group different from a RaaS?
The techniques stay constant. Huntress describes a single team that handles access, deployment and extortion, with no affiliates. Defenders gain a predictable attack chain: valid credentials over VPN or RDP, ShareFinder, WinRAR, FileZilla, encryption. They lose time: with no intermediary, the group moves from breach to deployment in under twenty-four hours according to Check Point.
Could our VPN credentials have been bought?
That is Check Point's hypothesis for SafePay: valid credentials most likely purchased on dark web marketplaces, then used against the VPN gateway. You do not control that market, but you do control what a credential alone allows. With phishing-resistant MFA and alerts on unusual logins, a purchased password is no longer enough to get in.
What should we take from the Ingram Micro incident?
That a global distributor confirmed ransomware on its internal systems in July 2025 and notified 42,521 people, according to The Register, after an intrusion claimed by SafePay. The lesson is twofold: supply chain availability depends on the remote access of every link, and notification of affected individuals can arrive months after the incident.

Let's talk about your compliance program.

Last updated: 2026-09-20