PYSA — Ransomware Profile
PYSA (Mespinoza) targeted education and healthcare sectors globally before declining operations in 2022 following arrests.Also tracked as
Mespinoza, Pysa
Tools & malware
- ADRecon Active Directory discovery
- Advanced Port Scanner Network discovery
- ChaChi RAT/Backdoor
- Chisel Tunneling tool
- Gasket Backdoor
- Gobfuscate Obfuscation tool
- Koadic Post-exploitation framework
- MagicSocks Tunneling tool
- Mespinoza Ransomware/Encryptor
- Mimikatz Credential theft
- PowerShell Empire Post-exploitation framework
- ProcDump Credential theft
- PsExec Lateral movement
- PYSA Ransomware/Encryptor
Vendor research
- Mespinoza Ransomware Gang Calls Victims "Partners," Attacks with Gasket, "MagicSocks" Tools Unit 42 (Palo Alto Networks)
- PYSA/Mespinoza Ransomware The DFIR Report
- FBI Flash: Increase in PYSA Ransomware Targeting Education Institutions CISA / FBI
- PYSA ransomware backdoors education orgs using ChaChi malware BleepingComputer
- FBI warns of escalating Pysa ransomware attacks on education orgs BleepingComputer