Rhysida is an active, financially motivated ransomware-as-a-service (RaaS) operation first observed in May 2023. It conducts data theft, ransomware deployment, and extortion through a public leak site, routinely threatening or publishing stolen data when victims do not pay. Microsoft tracks a Rhysida-associated cluster as Vanilla Tempest; Vice Spider has also been identified as an operator associated with the service. IBM X-Force has associated Rhysida activity with Endico, Broomstick/Oyster, Supper, Vidar, and the Tomb crypter. Rhysida has targeted public-sector entities, health-care providers, educational organizations, critical services, and commercial organizations internationally. Confirmed and widely reported incidents include the 2023 attack on the British Library and the 2026 compromise of portions of Berlin's state-administration environment. In the Berlin intrusion, attackers used a TerminalFix/ClickFix-style social-engineering lure to induce PowerShell execution, followed by DLL side-loading, steganographically concealed payloads, persistence, Active Directory and network discovery, tunneling, data exfiltration, and an attempted ransomware deployment. The operation subsequently extorted Berlin and published stolen material after payment was refused. Rhysida ransomware supports selective-directory encryption, partial encryption of large files, scheduled-task creation, and self-removal options. Early variants use AES-based file encryption with RSA-protected per-file key material. The operation combines encryption with theft-and-publication pressure, although some incidents emphasize data extortion even where encryption is prevented or not confirmed.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
73 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a ransomware attack against Axdia International.
Active RaaS operation using double extortion against education, government, manufacturing, IT, MSP, and healthcare targets.
Rhysida conducted a cyberattack against parts of Berlin's government administration network, stole data, demanded a 30-Bitcoin ransom, and published at least 1.2 million records after Berlin declined to pay.
Conducted a ransomware attack against Professional Retail Services, with the reported stolen data including employee, medical, financial, tax, credit, and banking documents.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.