Pysa Ransomware Under the Lens: A Deep-Dive Analysis
ID: 3d81b94f-24bc-5ae6-864e-88fb57075b7f
STIX ID: report--3d81b94f-24bc-5ae6-864e-88fb57075b7f
Feed Name: Cyble Blog
### Executive summary This Cyble Research Labs report provides a technical analysis of Pysa ransomware: a human-operated, double-extortion ransomware family observed since 2019 that is deployed after data exfiltration, enumerates fixed drives, encrypts targeted file types with AES-256 (appending .pysa), modifies registry legal notice entries, drops ransom notes, and uses self-deletion; the report includes a heat map of 190+ victims, IoCs (SHA-256, TOR leak site, contact email) and YARA rules for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
