PYSA, aka Mespinoza, is a malware capable of exfiltrating data and encrypting users critical files and data stored on their systems. The FBI issued a Flash alert on March 16, after an uptick on attacks this month against institutions in the education sector, particularly higher ed, K-12, and seminaries. Threat actors behind this ransomware were also found to conduct network reconnaissance using open-source tools like Advanced Port Scanner and Advanced IP Scanner.”]

