U.S. and European authorities warned that the PYSA ransomware group, also tracked as Mespinoza, was conducting double-extortion attacks against education and government organizations after stealing data and then encrypting Windows and Linux systems. The FBI said incidents affected higher education, K-12 schools, and seminaries across 12 U.S. states and the United Kingdom, while France's CERT-FR reported related intrusions against local government authorities. Stolen information included employment records, personally identifiable information, and payroll tax data, with victims pressured through ransom notes and threats to publish data on Tor-based leak sites.
Investigations and technical analyses showed the operators commonly gained initial access through compromised or brute-forced RDP credentials and phishing, then expanded access with reconnaissance and post-exploitation tools including Advanced IP Scanner, Advanced Port Scanner, PowerShell Empire, Koadic, Mimikatz, PsExec, Cobalt Strike, WinSCP, Chisel, and MEGA. The malware appended extensions such as .pysa, .locked, and .newversion, used AES encryption with RSA-protected keys, terminated services and security tools to improve encryption success, and in some cases changed local account passwords or modified Windows legal notice settings to display ransom demands. Researchers and law enforcement said the campaign disproportionately targeted high-value organizations, especially education, healthcare, and government entities, and urged mitigations including MFA, RDP hardening, segmentation, patching, least privilege, backups, and user awareness training.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
SentinelOne reported that Pysa's victim leak blog was offline as of early April 2022. The same analysis documented tactics observed across two investigated Pysa campaigns, including RDP access, password spraying, PsExec, Chisel, and Mega exfiltration.
Cyble published a technical analysis stating that Pysa had more than 190 victims worldwide and identifying the United States, United Kingdom, Canada, Spain, and Brazil as the most affected countries. The report also documented the group's leak site, ransom behavior, and indicators of compromise.
A Pysa ransomware sample later analyzed by Cyble was compiled on this date. The sample was described as an x86 Windows PE written in C/C++ that appends the .pysa extension and uses AES-256 encryption.
BleepingComputer reported on a PowerShell script used by the Pysa ransomware operation to scan compromised servers for folders matching 123 predefined keywords and upload matching files to an attacker-controlled server. The disclosure showed how Pysa prioritized financial, personal, credential, tax, student, and sensitive internal data to support ransom valuation and leak extortion.
BlackBerry published research on a new GoLang remote access trojan called ChaChi associated with Pysa-related intrusions. The report added technical detail on tooling used in the campaign, expanding public understanding of the group's post-compromise capabilities.
The FBI, coordinated with DHS-CISA, issued Alert Number CP-000142-MW warning of increased Pysa ransomware attacks. The alert said education institutions in 12 U.S. states and the United Kingdom were being increasingly targeted in double-extortion attacks.
CERT-FR issued an alert warning that a Mespinoza/Pysa ransomware gang was targeting French organizations, especially local government authorities. The alert described the operation as human-operated big-game hunting and noted a newer variant using the .newversion extension.
The FBI said it had become aware of Pysa attacks against U.S. and foreign government entities, educational institutions, private companies, and the healthcare sector starting in March 2020. Later reporting also described increased attacks from that period against U.S. and Canadian institutions.
ANSSI published technical findings from investigations into ransomware attacks on French local authorities, describing Windows and Python-based Pysa variants, their ransom notes, self-deletion behavior, and registry changes. The report also documented a separate PowerShell-based ransomware using the .newversion extension and overlapping ProtonMail contacts, along with intrusion tooling such as Mimikatz, PsExec, Empire, and a Go-based RAT.
CERT-FR reported receiving multiple infection reports involving the Pysa gang in France, particularly affecting local government authorities. The incidents involved brute-force activity, unauthorized RDP access, script deployment, credential theft, and antivirus disabling.
ANSSI reported that the Mespinoza ransomware family had been used since at least October 2018, establishing an explicit earliest known timeframe for the precursor later associated with Pysa. The report identified Mespinoza as the primary ransomware used in the analyzed attacks.
A January 2021 Pysa variant used the ransom note filename Readme.README.txt. This marked a documented evolution from earlier Readme.README note naming.
A new version of Mespinoza appeared using the .pysa extension, leading to the ransomware also being referred to as Pysa. Reporting places this transition in late 2019 to early 2020.
Mespinoza ransomware was first observed affecting victims, with early variants encrypting files using the .locked extension. Later reporting identifies this as the precursor to Pysa.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
cybereason.com
Open sourcesentinelone.com
Open sourceblog.cyble.com
Open sourcebleepingcomputer.com
Open sourcecert.ssi.gouv.fr
Open sourceic3.gov
Open sourcevirustotal.com
Open sourcecert.ssi.gouv.fr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.