Pysa

Inactive
Mespinosa is a ransomware which encrypts file using an asymmetric encryption and adds .pysa as file extension. According to dissectingmalware the extension "pysa" is probably derived from the Zanzibari Coin with the same name.
309 Victims
Jun 30, 2020 First Discovered
Sep 19, 2022 Last Discovered
1458 Days Inactive
0% Infostealer
0/1 Sites Online
Known Locations (1)
Pysa's Partners
pysa2bitc5ldeyfak4seeruqymqs4sj5wt5qkcq7aoyg4h2acqieywad.onion
Tools Used
CredentialTheft
Mimikatz, ProcDump, SessionGopher
DiscoveryEnum
ADRecon, Advanced IP Scanner, Advanced Port Scanner
Exfiltration
FileZilla, WinSCP
LOLBAS
PsExec, WMIC
Offsec
Chashell, Koadic, PowerShell Empire, PowerSploit
Victims (309)

Detailed victim list temporarily unavailable

This group has 309 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.