Ransomware Group intelligence
Pysa
InactiveTrack Pysa with 309 published victims and 1 known leak locations in a single intelligence view.
Overview
Pysa is tracked by Breach House as a ransomware group with 309 published victims.
Canada is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 3h ago | pysa2bitc5ldeyfak4seeruqymqs4sj5wt5qkcq7aoyg4h2acqieywad.onion |
Top Activity Sectors (17)
- Not identified 147
- Education 40
- Services 32
- Communication / Marketing 18
- Public Sector 11
- Healthcare / Pharma 10
- Manufacturing / Engineering 9
- IT 8
- Energy 8
- Finance / Legal / Insurance 6
- Retail / E-commerce 5
- Construction / Real Estate 4
- Transportation / Travel / Logistics 4
- Hospitality / Food & Beverage / Tourism 2
- Agriculture / Food 2
- NGOs / Associations 2
- Telecommunications 1
Typical Attacks (16)
▼How Pysa typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Pysa.
-
T1059.001 PowerShell Execution
What they do: Pysa has used Powershell scripts to deploy its ransomware.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.006 Python Execution
What they do: Pysa has used Python scripts to deploy ransomware.
What that means: Adversaries may abuse Python commands and scripts for execution.
-
T1569.002 Service Execution Execution
What they do: Pysa has used PsExec to copy and execute the ransomware.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
What they do: Pysa has modified the registry key “SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System” and added the ransom note.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1036.005 Match Legitimate Resource Name or Location Stealth
What they do: Pysa has executed a malicious executable by naming it svchost.exe.
What that means: Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
-
T1070.004 File Deletion Stealth
What they do: Pysa has deleted batch files after execution.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Pysa has the capability to stop antivirus services and disable Windows Defender.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1003.001 LSASS Memory Credential Access
What they do: Pysa can perform OS credential dumping using Mimikatz.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1110 Brute Force Credential Access
What they do: Pysa has used brute force attempts against a central management console, as well as some Active Directory accounts.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1552.001 Credentials In Files Credential Access
What they do: Pysa has extracted credentials from the password database before encrypting the files.
What that means: Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials.
-
T1016 System Network Configuration Discovery Discovery
What they do: Pysa can perform network reconnaissance using the Advanced IP Scanner tool.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1046 Network Service Discovery Discovery
What they do: Pysa can perform network reconnaissance using the Advanced Port Scanner tool.
What that means: Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
-
T1021.001 Remote Desktop Protocol Lateral Movement
What they do: Pysa has laterally moved using RDP connections.
What that means: Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP).
-
T1486 Data Encrypted for Impact Impact
What they do: Pysa has used RSA and AES-CBC encryption algorithm to encrypt a list of targeted file extensions.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Pysa can stop services and processes.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Pysa has the functionality to delete shadow copies.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (14)
▼Software Pysa has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Offensive security tooling
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Victims (309)
Search, filter and paginate the victim timeline for Pysa. Showing 101–200 of 309.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Diamond Box id1101 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Allard id1100 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Fincamex id1099 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Matthews id1098 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Oliviers id1097 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Poliview id1096 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Famisanar id1095 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Saludladera id1094 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Pjfitzpatrick id1093 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CDPO id1092 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Aebel id1091 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | HAC id1090 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ribasalvarez id1089 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Noorulislam id1088 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Grupocif id1087 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Cretsenbelledonne id1086 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Groupe Lefebvre M.R.P. id1085 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | The Masonic Home of Florida id1084 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Q3 Academy id1083 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Piedmont Orthopedics | OrthoAtlanta id1082 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MCLINC id1081 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | WHSE id1080 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | John Hardy id1079 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Marseille Provence id1078 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Alliance Building Services id1077 View details | Construction / Real Estate | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Wichita Sheet Metal id1076 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Illinois Valley Community College id1075 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Monty Holding Group id1074 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | The Dantherm Group id1073 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | The Sixth Form Bolton id1072 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Lindenwold id1071 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | The CFC id1070 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Dublin id1069 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Upper Columbia Academy id1068 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | The Seifert Logistics Group id1067 View details | Transportation / Travel / Logistics | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Uxbridge College id1066 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Assured Imaging id1065 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Grand Homes id1064 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | The Teka Group id1063 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ACE Glass id1062 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Bosley id1061 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MK Products id1060 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Myerscough College id1059 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | UCEL id1058 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Tor Vergata id1057 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | West Central Foodservice id1056 View details | Agriculture / Food | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Kuenne Gruppe id1055 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Irish Farmers Journals id1054 View details | Agriculture / Food | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CASES id1053 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Rafaela Alimentos id1052 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ASE Bucuresti id1051 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Heartland id1050 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Winters Independent School District id1049 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | IQA id1048 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Bakers S.A. Limited id1047 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Econocom id1046 View details | France | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Avelia id1045 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Mongoldford id1044 View details | NGOs / Associations | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CWF Group Inc. id1043 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Telhai id1042 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ayuntamiento de Guadarrama id1041 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Market Pioneer id1040 View details | Retail / E-commerce | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Roughrider Internation Ltd. id1039 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Bruce Turner id1038 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Mendes Júnior id1037 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Affinity Education id1036 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Gemitchellco id1035 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Rontis Medical id1034 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Mirai id1033 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Tech 2000 id1032 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Benchmark Family Services id1031 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Dayliff id1030 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Merchant Taylors' School id1029 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Riggins Company id1028 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | St. Margaretâs Hospice Care id1027 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Bene Ficencia id1026 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Grupo Infoar id1025 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | McKinney id1024 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Overlake Obstetricians & Gynecologists,PC id1023 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | St. Mary School Hyde Park id1022 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Torello Moving Strategies id1021 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Max. Aarts id1020 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Mid-Florida Pathology id1019 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Serinus Energy Plc id1018 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Outwest Express LLC id1017 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | King Henrys id1016 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Summit Appliance id1015 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Brickhaus id1014 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Finance Evolution id1013 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Nama Khoi Municipality id1012 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Thinkware id1011 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Brookfield Public Schools id1010 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Salesianum School id1009 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Provenza Floors id1008 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CCS id1007 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Palos Community Consolidated School District 118 id1006 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | DFW Communications,Inc. id1005 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | The FitzWimark School id1004 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ãstre Toten Kommune Voksenopplring id1003 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Blueknight Energy Partners id1002 View details | Energy | — | ||
|
No additional victim description available. |
|||||