logo

Pysa Ransomware Under the Lens: A Deep-Dive Analysis

ID: 3d81b94f-24bc-5ae6-864e-88fb57075b7f

STIX ID: report--3d81b94f-24bc-5ae6-864e-88fb57075b7f

Feed Name: Cyble Blog

Threat Score
80/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

### Executive summary This Cyble Research Labs report provides a technical analysis of Pysa ransomware: a human-operated, double-extortion ransomware family observed since 2019 that is deployed after data exfiltration, enumerates fixed drives, encrypts targeted file types with AES-256 (appending .pysa), modifies registry legal notice entries, drops ransom notes, and uses self-deletion; the report includes a heat map of 190+ victims, IoCs (SHA-256, TOR leak site, contact email) and YARA rules for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.