The French cybersecurity agency, France CERT (CERT-FR), has issued a warning about a new ransomware gang that has already carried out attacks on local government networks.
According to the security team, criminals are attacking using a new version of Mespinoza ransomware, also known as Pysa ransomware.
This ransomware was first detected in October 2019. According to reports published at the time, victims reported that their encrypted files were given the .locked extension.
A new version of Mespinoza was detected two months later, in December 2019. This time, the ransomware placed the .pysa extension on the encrypted files. For this ’ reason, it is also known as Pysa.
In these attacks, most of the victims were companies. This suggests that the group behind this new ransomware was primarily targeting large corporate networks, presumably so it could demand more ransom money.
Now, CERT-FR says the gang behind the Pysa ransomware is targeting French organizations. The agency has received alerts about multiple attacks.
We don't know how the ransomware gang infects its victims
CERT-FR said it is still investigating how the Pysa gang gained access to the victim's networks, but there are some clues that help investigators make some assumptions.
For example, CERT-FR stated that there is evidence to suggest that the Pysa gang is launching brute-force attacks on management consoles and Active Directory accounts.
Then, hackers steal databases with passwords and company
Victims also reported seeing unauthorized RDP connections to domain controllers.
Additionally, the Pysa gang deployed a version of the PowerShell Empire penetration-testing tool, stopped various products antivirus , and in some cases uninstalled Windows Defender.
CERT-FR reported that it also found a new file extension. Instead of .pysa, the ransomware was attaching the extension .newversion.
Researchers said they analyzed the ransomware and its encryption algorithms, but were unable to find any bugs that would allow victims to bypass paying the ransom and decrypt their files for free.
According to CERT-FR, the code of the Pysa ransomware is “specific and very short” and “based on public Python libraries”.
However, the attacks are not limited to France. Security have revealed that the ransomware gang is targeting both corporate and government networks around the world.
Big-game hunter
Mespinoza/Pysa is the latest ransomware gang to engage in “big game hunting” or “human-operated ransomware.” This means that the gangs target companies , compromise their networks, and then install the ransomware “hands-on” into their networks.
Other ransomware gangs that specialize in “big game hunting” include Ryuk, Revil (Sodinokibi), LockerGoga, RobbinHood, DoppelPaymer, Maze and many others.

