Back to Ransomware Database
Ransomware Group
pysa
Mespinosa is a ransomware which encrypts file using an asymmetric encryption and adds .pysa as file extension. According to dissectingmalware the extension "pysa" is probably derived from the Zanzibari Coin with the same name.
Known victims309
Threat Level
HIGH
Tactics, Techniques & Procedures (TTPs)
CredentialTheft
- Mimikatz
- ProcDump
- SessionGopher
DiscoveryEnum
- ADRecon
- Advanced IP Scanner
- Advanced Port Scanner
Exfiltration
- FileZilla
- WinSCP
LOLBAS
- PsExec
- WMIC
Offsec
- Chashell
- Koadic
- PowerShell Empire
- PowerSploit
Check If You’re Affected
Search our database to see if your organization appears in pysa’s victim list.
Try it nowFree⌘K
Try
risk score · threat categories · sources · age · confidence — in one request