Attacks involving the Mespinoza/Pysa ransomware
ID: 33037086-6f91-425e-a96c-3bf834288ee7
STIX ID: report--33037086-6f91-425e-a96c-3bf834288ee7
Threat Score
75/100
Uploaded: 2026-07-30
Published Date: 2026-07-30
Last Modified Date: 2026-08-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:A1
...
...
ANSSI describes recent opportunistic ransomware attacks targeting French local authorities leveraging Mespinoza/Pysa variants (Windows executable and Python .pyz) and a third PowerShell-based strain; the report includes sample filenames and hashes, ransom note characteristics, and observed TTPs such as RDP brute-force, PsExec, PowerShell scripts, credential theft (Mimikatz), post-exploitation tools (Empire), and a Go-based RAT, concluding these are financially motivated intrusions with significant impact on affected organisations.
