logo

Attacks involving the Mespinoza/Pysa ransomware

ID: 33037086-6f91-425e-a96c-3bf834288ee7

STIX ID: report--33037086-6f91-425e-a96c-3bf834288ee7

Threat Score

75/100

Uploaded: 2026-07-30

Published Date: 2026-07-30

Last Modified Date: 2026-08-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:A1
...
...
ANSSI describes recent opportunistic ransomware attacks targeting French local authorities leveraging Mespinoza/Pysa variants (Windows executable and Python .pyz) and a third PowerShell-based strain; the report includes sample filenames and hashes, ransom note characteristics, and observed TTPs such as RDP brute-force, PsExec, PowerShell scripts, credential theft (Mimikatz), post-exploitation tools (Empire), and a Go-based RAT, concluding these are financially motivated intrusions with significant impact on affected organisations.