Pysa
MITRE ATT&CK: S0583 View on attack.mitre.org
Aliases: Mespinoza, Pyza, Pysa, pysa
- First seen
- 2018-10-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 6 (6 malicious)
- Last IoC activity
- 2026-08-08 20:23:55
- Profile updated
- 2026-07-07 12:58:37
Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical
Context
Pysa is a ransomware that was first used in October 2018 and has been seen to target particularly high-value finance, government and healthcare organizations.
Recent IoC activity
6 malicious indicators in Maltiverse are attributed to Pysa (S0583). The 6 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 90cf35560032c380ddaaa05d9ed6baacbc7526a94a992a07fd02f92f371a8e92 | 2026-08-08 | 1 |
| file sample | 48355bd2a57d92e017bdada911a4b31aa7225c0b12231c9cbda6717616abaea3.zip | 2026-08-05 | 1 |
| file sample | 0f0014669bc10a7d87472cafc05301c66516857607b920ddeb3039f4cb8f0a50.exe | 2026-07-31 | 2 |
| file sample | svchost.exe | 2026-04-17 | 2 |
| file sample | f602319a51dfad374687a6d18f87c9f8e7b9cab956a4993c2ed83e7adad6e2db.bin | 2026-03-06 | 1 |
| file sample | 7c774062bc55e2d0e869d5d69820aa6e3b759454dbc926475b4db6f7f2b6cb14 | 2025-08-01 | 2 |
Detection coverage
- 5 YARA rules
- 695 Sigma rules
Malware & tools used
- System Network Configuration Discovery (attack-pattern)
- Python (attack-pattern)
- Credentials In Files (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- PowerShell (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Modify Registry (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Service Execution (attack-pattern)
- LSASS Memory (attack-pattern)
- Service Stop (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Brute Force (attack-pattern)
- File Deletion (attack-pattern)
- Network Service Discovery (attack-pattern)
Used by threat actors
- GOLD BURLAP (threat-actor)
Detection rules
- TRELLIX_ARC_Ransom_Mespinoza (yara-rule)
- ARKBIRD_SOLG_RAN_PYSA_Sept_2021_1 (yara-rule)
- BLACKBERRY_Mal_Backdoor_Chachi_RAT (yara-rule)
- DITEKSHEN_MALWARE_Win_PYSA (yara-rule)
- MALPEDIA_Win_Mespinoza_Auto (yara-rule)
Reports & references
- CrowdStrike — Report2021Gtr (report)
- secureworks.com — Gold Burlap (report)
- hhs.gov — Mespinoza Goldburlap Cyborgspider Analystnote Tlpwhite (report)
- docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
- ke-la.com — How Ransomware Gangs Find New Monetization Schemes And Evolve In Marketing (report)
- public.intel471.com — Ransomware As A Service 2020 Ryuk Maze Revil Egregor Doppelpaymer (report)
- vulnerability.ch — Ransomware And Date Leak Site Publication Time Analysis (report)
- cyborgsecurity.com — Hunting Ransomware Inhibiting System Backup Or Recovery (report)
- hornetsecurity.com — Leakware Ransomware Hybrid Attacks (report)
- splunk.com — Gone In 52 Seconds And 42 Minutes A Comparative Analysis Of Ransomware Encryption Speed (report)
- splunk.com — An Empirically Comparative Analysis Of Ransomware Binaries (report)
- Broadcom/Symantec — Sed Fy22Q2 Ses Ransomware Threat Landscape Wp (report)
- media.kasperskycontenthub.com — Common Ttps Of The Modern Ransomware Low Res (report)
- Kaspersky — 106824 (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 002 (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 002 (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 003 (report)
- ic3.gov — 210316 (report)
- blog.malwarebytes.com — Pysa The Ransomware Attacking Schools (report)
- blog.cyble.com — Pysa Ransomware Under The Lens A Deep Dive Analysis (report)
- blogs.blackberry.com — Pysa Loves Chachi A New Golang Rat (report)
- dissectingmalwa.re — Another One For The Collection Mespinoza Pysa Ransomware (report)
- id-ransomware.blogspot.com — Mespinoza Ransomware (report)
- thedfirreport.com — Pysa Mespinoza Ransomware (report)
- twitter.com — 1347223969984897026 (report)