Pysa

S0583

Malware.View on attack.mitre.org

About this malware

Pysa is a ransomware that was first used in October 2018 and has been seen to target particularly high-value finance, government and healthcare organizations.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1003.001
LSASS Memory

Pysa can perform OS credential dumping using Mimikatz.

T1016
System Network Configuration Discovery

Pysa can perform network reconnaissance using the Advanced IP Scanner tool.

T1021.001
Remote Desktop Protocol

Pysa has laterally moved using RDP connections.

T1036.005
Match Legitimate Resource Name or Location

Pysa has executed a malicious executable by naming it svchost.exe.

T1046
Network Service Discovery

Pysa can perform network reconnaissance using the Advanced Port Scanner tool.

T1059.001
PowerShell

Pysa has used Powershell scripts to deploy its ransomware.

T1059.006
Python

Pysa has used Python scripts to deploy ransomware.

T1070.004
File Deletion

Pysa has deleted batch files after execution.

T1110
Brute Force

Pysa has used brute force attempts against a central management console, as well as some Active Directory accounts.

T1112
Modify Registry

Pysa has modified the registry key “SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System” and added the ransom note.

T1486
Data Encrypted for Impact

Pysa has used RSA and AES-CBC encryption algorithm to encrypt a list of targeted file extensions.

T1489
Service Stop

Pysa can stop services and processes.

T1490
Inhibit System Recovery

Pysa has the functionality to delete shadow copies.

T1552.001
Credentials In Files

Pysa has extracted credentials from the password database before encrypting the files.

T1569.002
Service Execution

Pysa has used PsExec to copy and execute the ransomware.

View all 16 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. CERT-FR PYSA April 2020 Open source
    CERT-FR. (2020, April 1). ATTACKS INVOLVING THE MESPINOZA/PYSA RANSOMWARE. Retrieved March 1, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.