Pysa Ransomware

Description Summary

Mespinosa is a ransomware which encrypts file using an asymmetric encryption and adds .pysa as file extension. According to dissectingmalware the extension "pysa" is probably derived from the Zanzibari Coin with the same name.

Threat Actor

Operators of Mespinosa/Pysa; targeted education, government and healthcare; subject of FBI and CERT-FR advisories.

Technical Indicators

Encryption Extension
.pysa
Encryption Algorithm
AES (CBC) + RSA (asymmetric)
Ransom Note Name
Readme.README.txt
Targeted Industries
Education, Government, Healthcare
First Seen
October 2019 (as Mespinosa)
Last Seen
2022
Geographical Location
United States, United Kingdom, Europe

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
Exfiltration x 1 T1567 Exfiltration Over Web Service (leak site)
Initial Access x 2 T1190 Exploit Public-Facing Application
T1078 Valid Accounts