Description Summary
Mespinosa is a ransomware which encrypts file using an asymmetric encryption and adds .pysa as file extension. According to dissectingmalware the extension "pysa" is probably derived from the Zanzibari Coin with the same name.
Threat Actor
Operators of Mespinosa/Pysa; targeted education, government and healthcare; subject of FBI and CERT-FR advisories.
Technical Indicators
Encryption Extension
.pysa
Encryption Algorithm
AES (CBC) + RSA (asymmetric)
Ransom Note Name
Readme.README.txt
Targeted Industries
Education, Government, Healthcare
First Seen
October 2019 (as Mespinosa)
Last Seen
2022
Geographical Location
United States, United Kingdom, Europe
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Impact x 2 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| Exfiltration x 1 | T1567 | Exfiltration Over Web Service (leak site) |
| Initial Access x 2 | T1190 | Exploit Public-Facing Application |
| T1078 | Valid Accounts |