Skip to main content
Back to Ransomware Database
Ransomware Group

pysa

Mespinosa is a ransomware which encrypts file using an asymmetric encryption and adds .pysa as file extension. According to dissectingmalware the extension "pysa" is probably derived from the Zanzibari Coin with the same name.

Known victims309

Threat Level

HIGH

Tactics, Techniques & Procedures (TTPs)

CredentialTheft

  • Mimikatz
  • ProcDump
  • SessionGopher

DiscoveryEnum

  • ADRecon
  • Advanced IP Scanner
  • Advanced Port Scanner

Exfiltration

  • FileZilla
  • WinSCP

LOLBAS

  • PsExec
  • WMIC

Offsec

  • Chashell
  • Koadic
  • PowerShell Empire
  • PowerSploit
0

Check If You’re Affected

Search our database to see if your organization appears in pysa’s victim list.

Try it nowFree⌘K
Try

risk score · threat categories · sources · age · confidence — in one request