Pysa

MITRE ATT&CK: S0583 View on attack.mitre.org

Aliases: Mespinoza, Pyza, Pysa, pysa

First seen
2018-10-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows
Related IoCs
6 (6 malicious)
Last IoC activity
2026-08-08 20:23:55
Profile updated
2026-07-07 12:58:37

Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical

Context

Pysa is a ransomware that was first used in October 2018 and has been seen to target particularly high-value finance, government and healthcare organizations.

Recent IoC activity

6 malicious indicators in Maltiverse are attributed to Pysa (S0583). The 6 most recently updated:

Detection coverage

  • 5 YARA rules
  • 695 Sigma rules

Malware & tools used

  • System Network Configuration Discovery (attack-pattern)
  • Python (attack-pattern)
  • Credentials In Files (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • PowerShell (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Modify Registry (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • Service Execution (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Service Stop (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Brute Force (attack-pattern)
  • File Deletion (attack-pattern)
  • Network Service Discovery (attack-pattern)

Used by threat actors

Detection rules

  • TRELLIX_ARC_Ransom_Mespinoza (yara-rule)
  • ARKBIRD_SOLG_RAN_PYSA_Sept_2021_1 (yara-rule)
  • BLACKBERRY_Mal_Backdoor_Chachi_RAT (yara-rule)
  • DITEKSHEN_MALWARE_Win_PYSA (yara-rule)
  • MALPEDIA_Win_Mespinoza_Auto (yara-rule)

Reports & references

  • CrowdStrike — Report2021Gtr (report)
  • secureworks.com — Gold Burlap (report)
  • hhs.gov — Mespinoza Goldburlap Cyborgspider Analystnote Tlpwhite (report)
  • docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
  • ke-la.com — How Ransomware Gangs Find New Monetization Schemes And Evolve In Marketing (report)
  • public.intel471.com — Ransomware As A Service 2020 Ryuk Maze Revil Egregor Doppelpaymer (report)
  • vulnerability.ch — Ransomware And Date Leak Site Publication Time Analysis (report)
  • cyborgsecurity.com — Hunting Ransomware Inhibiting System Backup Or Recovery (report)
  • hornetsecurity.com — Leakware Ransomware Hybrid Attacks (report)
  • splunk.com — Gone In 52 Seconds And 42 Minutes A Comparative Analysis Of Ransomware Encryption Speed (report)
  • splunk.com — An Empirically Comparative Analysis Of Ransomware Binaries (report)
  • Broadcom/Symantec — Sed Fy22Q2 Ses Ransomware Threat Landscape Wp (report)
  • media.kasperskycontenthub.com — Common Ttps Of The Modern Ransomware Low Res (report)
  • Kaspersky — 106824 (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 002 (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 002 (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 003 (report)
  • ic3.gov — 210316 (report)
  • blog.malwarebytes.com — Pysa The Ransomware Attacking Schools (report)
  • blog.cyble.com — Pysa Ransomware Under The Lens A Deep Dive Analysis (report)
  • blogs.blackberry.com — Pysa Loves Chachi A New Golang Rat (report)
  • dissectingmalwa.re — Another One For The Collection Mespinoza Pysa Ransomware (report)
  • id-ransomware.blogspot.com — Mespinoza Ransomware (report)
  • thedfirreport.com — Pysa Mespinoza Ransomware (report)
  • twitter.com — 1347223969984897026 (report)

External references