H-ISAC TLP White Finished Intelligence Reports: Increase in PYSA Ransomware – March 18, 2021

p>The Federal Bureau of Investigation has published CP-000142-MW, an alert focused on an Increase in PYSA Ransomware targeting multiple sectors including educational institutions and healthcare organizations.

 

PYSA, also known as Mespinoza, is malware capable of exfiltrating data and encrypting users’ critical files and data stored on their systems. The unidentified cyber actors have specifically targeted the healthcare sector, higher education, K-12 schools, and seminaries. The actors use PYSA ransomware to exfiltrate data from victims prior to encrypting victim’s systems to use as leverage in eliciting ransom payments.