{
  "family": "pykspa",
  "sample_count": 169,
  "category": "worm",
  "description": "Pykspa is a worm that spreads through Skype by sending messages containing download links to other Skype users. When a recipient downloads and runs the file, Pykspa infects the system, extracts personal information, and communicates with its command-and-control (C2) servers. To make its C2 infrastructure resilient, Pykspa uses a domain generation algorithm (DGA) to produce the domain names it contacts. It is documented by Fraunhofer FKIE's Malpedia, with analysis referenced from Akamai.",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [],
  "enrichment_level": "curated_sourced",
  "faq": [
    {
      "@type": "Question",
      "name": "What is Pykspa?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Pykspa is a worm that spreads through Skype. It sends messages with download links to other Skype users, and infects systems when those files are downloaded and run."
      }
    },
    {
      "@type": "Question",
      "name": "How does Pykspa spread?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Pykspa propagates by sending Skype messages containing download links to a victim's contacts. Recipients who download and execute the linked file become infected, allowing the worm to spread further."
      }
    },
    {
      "@type": "Question",
      "name": "What does Pykspa do once it infects a system?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "After infection, Pykspa extracts personal information and communicates with command-and-control servers. It uses a domain generation algorithm (DGA) to generate the domains it contacts, which helps its infrastructure resist takedown."
      }
    },
    {
      "@type": "Question",
      "name": "What sources document Pykspa?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Pykspa is profiled in Fraunhofer FKIE's Malpedia, with its Skype-based spreading and DGA behaviour described in analysis referenced from Akamai."
      }
    }
  ],
  "faq_count": 4,
  "mitre_attack": [],
  "cisa_advisory": null,
  "last_updated": "2026-06-11",
  "sources": [
    {
      "name": "Malpedia (Fraunhofer FKIE): Pykspa",
      "url": "https://malpedia.caad.fkie.fraunhofer.de/details/win.pykspa"
    }
  ],
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}