Ransomware Group intelligence
Pysa
InactiveTrack Pysa with 309 published victims and 1 known leak locations in a single intelligence view.
Overview
Pysa is tracked by Breach House as a ransomware group with 309 published victims.
Canada is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 2h ago | pysa2bitc5ldeyfak4seeruqymqs4sj5wt5qkcq7aoyg4h2acqieywad.onion |
Top Activity Sectors (17)
- Not identified 147
- Education 40
- Services 32
- Communication / Marketing 18
- Public Sector 11
- Healthcare / Pharma 10
- Manufacturing / Engineering 9
- IT 8
- Energy 8
- Finance / Legal / Insurance 6
- Retail / E-commerce 5
- Construction / Real Estate 4
- Transportation / Travel / Logistics 4
- Hospitality / Food & Beverage / Tourism 2
- Agriculture / Food 2
- NGOs / Associations 2
- Telecommunications 1
Typical Attacks (16)
▼How Pysa typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Pysa.
-
T1059.001 PowerShell Execution
What they do: Pysa has used Powershell scripts to deploy its ransomware.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.006 Python Execution
What they do: Pysa has used Python scripts to deploy ransomware.
What that means: Adversaries may abuse Python commands and scripts for execution.
-
T1569.002 Service Execution Execution
What they do: Pysa has used PsExec to copy and execute the ransomware.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
What they do: Pysa has modified the registry key “SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System” and added the ransom note.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1036.005 Match Legitimate Resource Name or Location Stealth
What they do: Pysa has executed a malicious executable by naming it svchost.exe.
What that means: Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
-
T1070.004 File Deletion Stealth
What they do: Pysa has deleted batch files after execution.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Pysa has the capability to stop antivirus services and disable Windows Defender.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1003.001 LSASS Memory Credential Access
What they do: Pysa can perform OS credential dumping using Mimikatz.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1110 Brute Force Credential Access
What they do: Pysa has used brute force attempts against a central management console, as well as some Active Directory accounts.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1552.001 Credentials In Files Credential Access
What they do: Pysa has extracted credentials from the password database before encrypting the files.
What that means: Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials.
-
T1016 System Network Configuration Discovery Discovery
What they do: Pysa can perform network reconnaissance using the Advanced IP Scanner tool.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1046 Network Service Discovery Discovery
What they do: Pysa can perform network reconnaissance using the Advanced Port Scanner tool.
What that means: Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
-
T1021.001 Remote Desktop Protocol Lateral Movement
What they do: Pysa has laterally moved using RDP connections.
What that means: Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP).
-
T1486 Data Encrypted for Impact Impact
What they do: Pysa has used RSA and AES-CBC encryption algorithm to encrypt a list of targeted file extensions.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Pysa can stop services and processes.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Pysa has the functionality to delete shadow copies.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (14)
▼Software Pysa has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Offensive security tooling
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Victims (309)
Search, filter and paginate the victim timeline for Pysa. Showing 301–309 of 309.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Logansport Community School Corporation id901 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | FCS Financial id900 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Danko Emergency Equipment id899 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | HVAC Facility & Plant Maintenance Tools id898 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | HPW id897 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | My Cloud Star id896 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Hackney Council id491 View details | United Kingdom | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Nonin Medical id474 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Durham Radio id433 View details | Canada | Other | — | |
|
No additional victim description available. |
|||||