PYSA Ransomware Dominate November Round Of Extortion Attacks

Share post:

PYSA ransomware group (aka Mespinoza) contributed in no small measure to the increase in the use of double extortion tools during ransomware attacks.

While attacks on government organizations have increased by 400%, the PYSA Ransomware group recorded an increase of up to 50% when it comes to the infection rate.

Double extortion simply means that attackers extort money for ransomware attacks and steal data from the company in order to extort money again and increase the pressure on the victim.

For PYSA ransomware group, the threat actors exfiltrated data from the compromised network then encrypted the original to disrupt the operation.

After that, the stolen files are used as leverage in ransomware negotiations. With the stolen files in their possession, the attackers threaten organizations to pay the ransom or risk that their data will be published.

In its report on the growing trends that deal with ransomware attacks, the report of the NCC Group reveals: “While selling ransomware-as-a-service has seen a surge in popularity over the last year, this is a rare instance of a group forgoing a request for a ransom and offering access to IT infrastructure – but we may see copycat attacks in 2022 and beyond.”

For more information, read the original story in BleepingComputer.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Leaked documents may show the inside of China’s hacking strategy

Documents apparently stolen by disgruntled employees to embarrass their firm may give insight into China's cyber

Abuse of valid accounts by threat actors hits a high, says IBM

Attackers are finding that obtaining valid credentials is an easier route to achieving their goals, s

Cyber Security Today, Feb. 21, 2024 – A patch warning from ConnectWise, the latest ransomware news, and more

This episode reports on a report comparing business email compromise attacks against ransomware

UK leads takedown of LockBit ransomware gang’s website

The LockBit ransomware gang’s website has been seized, several news agencies reported late Monday. The Reuters news agency and The Register are carrying stories based on a new splash screen that has appeared on the gang’s website. It says, “This site is now under the control of the National Crime Agency of the UK, working

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways