Mespinoza — also tracked as Pysa — is a human-operated ransomware family first observed in late 2019, attributed by CISA and the FBI to financially motivated cybercriminal actors. It belongs to the ransomware category, specifically targeting large enterprises and critical infrastructure sectors through targeted, manual attacks rather than automated worm-like propagation.
Mespinoza gains initial access via compromised RDP credentials, phishing emails with malicious attachments, or exploitation of vulnerable internet-facing services. Once inside, it uses living-off-the-land binaries (LOLBins) such as PowerShell and PsExec for lateral movement and to deploy the ransomware payload. The ransomware encrypts files using a combination of AES-256 and RSA-4096, appending the extension .pysa to encrypted files. It employs a custom-built data exfiltration tool called "Exbyte" to steal sensitive data before encryption, and communicates with command-and-control (C2) infrastructure over HTTPS for key negotiation and exfiltration. Persistence is achieved through scheduled tasks and service creation, while evasion techniques include disabling Windows Defender, deleting Volume Shadow Copies (vssadmin.exe) to prevent recovery, and avoiding encryption of files in system directories to maintain system functionality.
Mespinoza was first observed in September 2019 with campaigns targeting organizations in the United States, Europe, and Latin America. In 2020, it gained notoriety by attacking multiple U.S. government agencies, including the Texas Department of Transportation, and has been linked to the disruption of healthcare and education sectors. No public CVEs are uniquely associated with the ransomware, but it commonly exploits known vulnerabilities (e.g., CVE-2019-0708 BlueKeep) for initial access when targeting unpatched systems.
Indicators include file extensions .pysa or .mespinoza appended to encrypted files, and a ransom note named "How_to_decrypt.README" placed in affected directories. Network IOCs include connections to IP addresses on ports 443, 3389, and 445, often using custom User-Agent strings such as "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0". Known file hashes are updated regularly, but CISA’s #StopRansomware advisory (2021) lists specific SHA-256 hashes of Mespinoza samples. Behavioral signatures include execution of bcdedit.exe to disable recovery mode and use of wevtutil.exe to clear event logs.
Mespinoza causes severe financial damage through double extortion: data exfiltration followed by encryption, with ransom demands ranging from hundreds of thousands to millions of dollars. Affected sectors include government, healthcare, education, and manufacturing, with operations often requiring weeks to fully recover. According to CISA, successful attacks have led to significant data loss, operational downtime, and regulatory penalties for exposed sensitive information.
Defenders should enforce multi-factor authentication for RDP, apply patches for known vulnerabilities (especially BlueKeep — CVE-2019-0708), and monitor for anomalous RDP and PowerShell activity using Sysmon and EDR tools. CISA recommends implementing network segmentation, disabling SMBv1, and maintaining offline backups. Detection rules are available in the CISA AA21-291A advisory and MITRE ATT&CK techniques T1486 (Data Encrypted for Impact) and T1566 (Phishing).
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.