Mespinosa is a ransomware which encrypts file using an asymmetric encryption and adds .pysa as file extension. According to dissectingmalware the extension "pysa" is probably derived from the Zanzibari Coin with the same name. Known victims: 309
Objectives
Executive Summary
Pysa is a ransomware threat actor that encrypts files using asymmetric encryption and appends the .pysa extension to encrypted files. The group primarily operates with financial gain as their main motivation, targeting organizations for ransom payment. Pysa has been active since July 2020 and continues to pose a significant threat to various industries, particularly those with high financial value.
Goals & Targeting
Pysa’s strategic objectives are focused on maximizing financial gain through the deployment of ransomware. The group targets sectors with significant data value and operational disruption potential, such as healthcare and education, where the need for rapid data recovery is critical. Their targeting profile suggests a preference for mid-sized organizations with weaker cybersecurity defenses but high recovery costs to increase the likelihood of successful ransom payments.
Enhanced Description
Pysa is a sophisticated ransomware variant known for its asymmetric encryption methodology. The malware encrypts victim files using an asymmetric cipher and appends the .pysa extension to denote encrypted files. The name 'Pysa' is suspected to be derived from Zanzibari Coin, which was an earlier cryptocurrency associated with similar naming conventions. This ransomware group operates under a clear financial motivation, seeking monetary payouts from victims through decryptor payment portals. Pysa primarily targets organizations across various sectors, including healthcare and education, leveraging their high data sensitivity and recovery needs to maximize ransom negotiations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The Pysa campaigns have been observed to target organizations in an indiscriminate manner, utilizing various infection vectors such as phishing emails and malicious links. Their operational tempo indicates active campaigns since 2020, with a steady increase in victim count over time. Notable past operations include multiple ransomware incidents across different countries, primarily targeting critical infrastructure sectors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available intelligence on Pysa is moderate due to limited historical operational data and a lack of detailed TTP analysis. The most critical gaps include specifics on their exact targeting criteria, full attack chain details, and known infrastructure.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics