Rhysida is a financially motivated ransomware group and ransomware-as-a-service operation active since at least 2023. It is widely tracked under the name Rhysida and has been discussed in connection with a possible operational lineage or rebrand from Vice Society, although that relationship is not universally confirmed and should be treated cautiously. The group is known for double-extortion activity in which data theft accompanies encryption and victims are pressured through public leak-site exposure. Reporting indicates a high rate of public data release relative to its claimed victim volume. Rhysida has targeted organizations across multiple sectors, including healthcare, construction, engineering, and other corporate environments, and has been associated with attacks on critical infrastructure and healthcare entities. Victimology shows a broad, opportunistic pattern rather than a narrowly specialized vertical focus, though healthcare has been a recurring target. Operationally, Rhysida is associated with common enterprise intrusion tradecraft used in modern ransomware campaigns. Reporting links the group to the use of malware and access tooling such as SystemBC and the Oyster backdoor, and to access obtained through initial access brokers including Woodgnat, also known as KongTuke. In those broader intrusion ecosystems, access has been established through social engineering, malvertising and SEO poisoning, fake software installers, compromised websites, phishing, and abuse of legitimate remote management or administrative tools. Rhysida has also been noted for abusing code-signing certificates in its operations to improve payload trust and evade defenses. The group’s activity fits the broader cybercrime affiliate model in which specialized access providers, loaders, backdoors, and post-compromise tooling are combined to enable ransomware deployment, lateral movement, persistence, and data theft. Rhysida has been publicly linked in reporting to intrusion chains involving enterprise backdoors and brokered access later monetized through ransomware extortion. Rhysida is a cybercriminal threat actor, not a nation-state actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
71 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as an example of a threat actor known to abuse code-signing certificates.
Mentioned only as background comparison regarding code-signing certificate abuse.
Named as one of the ransomware groups publicly linked to Woodgnat as a downstream partner or affiliate receiving sold access.
Named as a ransomware group linked to the malware activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.