Malware.View on attack.mitre.org
Pysa is a ransomware that was first used in October 2018 and has been seen to target particularly high-value finance, government and healthcare organizations.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
|
| T1016 System Network Configuration Discovery |
Pysa can perform network reconnaissance using the Advanced IP Scanner tool. |
| T1021.001 Remote Desktop Protocol |
Pysa has laterally moved using RDP connections. |
| T1036.005 Match Legitimate Resource Name or Location |
Pysa has executed a malicious executable by naming it svchost.exe. |
| T1046 Network Service Discovery |
Pysa can perform network reconnaissance using the Advanced Port Scanner tool. |
| T1059.001 PowerShell |
Pysa has used Powershell scripts to deploy its ransomware. |
| T1059.006 Python |
Pysa has used Python scripts to deploy ransomware. |
| T1070.004 File Deletion |
Pysa has deleted batch files after execution. |
| T1110 Brute Force |
Pysa has used brute force attempts against a central management console, as well as some Active Directory accounts. |
| T1112 Modify Registry |
Pysa has modified the registry key “SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System” and added the ransom note. |
| T1486 Data Encrypted for Impact |
Pysa has used RSA and AES-CBC encryption algorithm to encrypt a list of targeted file extensions. |
| T1489 Service Stop |
Pysa can stop services and processes. |
| T1490 Inhibit System Recovery |
Pysa has the functionality to delete shadow copies. |
| T1552.001 Credentials In Files |
Pysa has extracted credentials from the password database before encrypting the files. |
| T1569.002 Service Execution |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.