Mespinoza, widely known through its PYSA variant, is a human-operated ransomware family used in financially motivated double-extortion attacks. Its operators steal sensitive information before encrypting files and threaten to publish or sell the stolen data if victims refuse payment. Targets have included government entities, French local authorities, private companies, healthcare organizations, and educational institutions, including schools and universities in the United States and United Kingdom.
PYSA uses hybrid AES-CBC and RSA encryption to render selected files inaccessible while excluding system-critical files and directories. An analyzed Windows implementation is written in C++ and uses the CryptoPP library; Python-based variants have also been identified. The ransomware creates ransom notes, modifies Windows legal-notice settings to display ransom demands, and removes its executable and supporting scripts after execution. Analyzed payloads lack autonomous propagation. Linux encryptors associated with Mespinoza have also been identified, including versions intended for VMware ESXi environments.
Operators gain access through phishing or compromised credentials, including brute-forced Active Directory and RDP credentials. Intrusions involve Mimikatz for credential dumping, Advanced IP Scanner and Advanced Port Scanner for network discovery, RDP and PsExec for lateral movement, and PowerShell for ransomware deployment and disabling security controls. Operators also delete recovery snapshots and shadow copies. Data theft has used WinSCP and PowerShell scripts that search for sensitive financial, personal, educational, and credential-related information and upload matching files to attacker-controlled servers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
Этот вариант распространяется с помощью грубых атак на консоли управления и аккаунты Active Directory...
AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine... Agent Tesla has the ability to extract credentials from configuration or support files... APT33 has used a variety of publicly available tools like LaZagne to gather credentials.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
Le script « step1.ps1 » est chargé de lister les fichiers présents sur le système.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
Les fichiers créés par la routine de chiffrement portent l’extension « .pysa » [T1486].
L’arrêt des services antiviraux et de divers autres services et processus, ainsi que la désinstallation de WINDOWS DEFENDER [T1089].
114 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
71 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named only in a related-articles reference; no details about its behavior are discussed in the main content.
Ransomware used to encrypt and steal victim data in attacks against healthcare-related organizations.
Ransomware family referenced in related article titles involving attacks on school districts.
Pysa is a ransomware variant known for targeting organizations, encrypting files, and demanding payment for decryption. It has been involved in attacks against healthcare providers, leading to data breaches and regulatory penalties.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.