Pysa, also known as Mespinoza and derived from the phrase “Protect Your System Amigo,” is a human-operated ransomware family associated with double-extortion intrusions against organizations in government, education, healthcare, and other private-sector environments. First observed as Mespinoza in 2019 and later widely tracked as Pysa, it encrypts victim data and pressures organizations by threatening to leak stolen information. The operation has been linked to campaigns against high-value targets, including local government authorities and educational institutions, and has also been reported targeting healthcare and business networks across multiple countries.
Pysa intrusions are characterized by hands-on-keyboard activity rather than self-propagation. Reported initial access methods include phishing and the use of compromised or brute-forced credentials, particularly through Remote Desktop Protocol and Active Directory accounts. Operators have used common administrative and offensive tooling for post-compromise activity, including credential theft, privilege escalation, lateral movement, and reconnaissance. Observed tradecraft includes extraction of credentials from password databases, network reconnaissance with scanning tools, use of PowerShell and PsExec for deployment, disabling or removing security products, and deletion of restore points and shadow copies to hinder recovery. Data theft is a core part of the operation’s extortion model, and operators have used scripts to identify and exfiltrate financially, legally, and operationally sensitive information before encryption.
Windows variants of Pysa have been described as implemented in C++ using hybrid AES and RSA encryption, while other observed variants have included Python- and PowerShell-based encryptors. The malware typically appends the .pysa extension to encrypted files, though other extensions have also been observed in some variants. It drops ransom notes and may write ransom text into Windows legal notice settings so the message is displayed to users. Pysa commonly avoids encrypting selected system-critical files and directories to preserve system operability long enough for ransom negotiation. Some variants create a mutex to prevent duplicate execution and use batch-script cleanup to delete the ransomware after launch. Linux encryptors associated with the operation have also been reported, particularly in the broader trend of ransomware targeting virtualized enterprise infrastructure such as ESXi environments.
Pysa is best understood as a financially motivated ransomware operation that combines credential theft, reconnaissance, exfiltration, defense evasion, and manual deployment to maximize impact on enterprise victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
These brute-force attacks were followed by the exfiltration of a company's accounts & passwords database. Victim organizations also reported seeing unauthorized RDP connections to their domain controllers
Victim organizations also reported seeing unauthorized RDP connections to their domain controllers, and the deployment of Batch and PowerShell scripts.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
Victim organizations also reported seeing unauthorized RDP connections to their domain controllers, and the deployment of Batch and PowerShell scripts.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
the Pysa gang also deployed a version of the PowerShell Empire penetration-testing tool, stopped various antivirus products, and even uninstalled Windows Defender in some instances.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
These brute-force attacks were followed by the exfiltration of a company's accounts & passwords database. Victim organizations also reported seeing unauthorized RDP connections to their domain controllers
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
Этот вариант распространяется с помощью грубых атак на консоли управления и аккаунты Active Directory...
AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine... Agent Tesla has the ability to extract credentials from configuration or support files... APT33 has used a variety of publicly available tools like LaZagne to gather credentials.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
...they use the Advanced Port Scanner and the Advanced IP Scanner tools... which are port scanning and information gathering tools that enable users to discover and gather information on services running on network computers.
Le script « step1.ps1 » est chargé de lister les fichiers présents sur le système.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
Les fichiers créés par la routine de chiffrement portent l’extension « .pysa » [T1486].
L’arrêt des services antiviraux et de divers autres services et processus, ainsi que la désinstallation de WINDOWS DEFENDER [T1089].
114 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
67 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named only in a related-articles reference; no details about its behavior are discussed in the main content.
Ransomware used to encrypt and steal victim data in attacks against healthcare-related organizations.
Ransomware family referenced in related article titles involving attacks on school districts.
Pysa is a ransomware variant known for targeting organizations, encrypting files, and demanding payment for decryption. It has been involved in attacks against healthcare providers, leading to data breaches and regulatory penalties.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.