Rhysida is a ransomware-as-a-service operation active since May 2023. It conducts double-extortion attacks, stealing victim data and encrypting systems before demanding cryptocurrency payments and threatening public disclosure. Victims have included government entities, healthcare and public-health organizations, educational institutions, manufacturers, technology companies, managed service providers, the British Library, the Chilean Army, and Holding Slovenske Elektrarne. Activity has been reported across Western Europe, the Americas, Australia, and other regions.
Rhysida commonly obtains initial access through phishing; U.S. government guidance also identifies compromised VPN credentials lacking multifactor authentication and exploitation of the Zerologon vulnerability as observed access methods. Operators have used Cobalt Strike, PsExec, and PowerShell tooling to deploy payloads, impair endpoint defenses, remove shadow copies, alter Remote Desktop Protocol settings, and clear Windows event logs. The ransomware can establish scheduled-task persistence and change the desktop wallpaper to display its extortion message.
The locker encrypts eligible files using AES in CTR mode with per-file keying material generated through LibTomCrypt's ChaCha20 pseudorandom-number generator and protected using an embedded 4096-bit RSA public key. A publicly reported implementation weakness in the ransomware's time-seeded random-number generation enabled researchers to develop a decryptor for affected files. Rhysida's operators and precise geographic origin remain unconfirmed; an asserted connection to Vice Society is not established conclusively.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Berlin’s state government confirmed it is dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network. The ransomware group Rhysida claimed responsibility, alleging theft of 5.79 TB of data.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Files encrypted by Rhysida ransomware can be successfully decrypted, due to a implementation vulnerability discovered by Korean researchers and leveraged to create a decryptor. Rhysida is a relatively new ransomware-as-a-service gang that engages in double extortion.
The Rhysida and Interlock groups, which are known to attack healthcare and other critical infrastructure, have similar TTPs and encryption binaries, leading to some speculation of a connection between the two groups.
US government agencies released an advisory note on Rhysida last week, stating that the “emerging ransomware variant” had been deployed against the education, manufacturing, IT and government sectors since May.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Attackers then distributed the signed malware through tactics such as search manipulation and malicious ads, where users are more likely to trust what they encounter.
Further analysis revealed that Fox Tempest expanded its offerings earlier this year by providing customers with pre-configured virtual machines hosted through Cloudzy infrastructure. Users could upload malware to these systems and receive digitally signed binaries generated through certificates controlled by the group.
Persistence T1053.005 Scheduled Task/Job: Scheduled Task When executed with the argument -S, it will create a scheduled task named Rhsd that will execute the ransomware
Execution T1059.001 Command and Scripting Interpreter: PowerShell It uses PowerShell to create scheduled task named Rhsd pointing to the ransomware.
The signed files often impersonated trusted software brands such as Microsoft Teams, AnyDesk, PuTTY, and Webex, making them appear more credible to potential victims.
T1070.001 Indicator Removal: Clear Windows Event Logs It uses wevtutil.exe to clear Windows event logs.
Microsoft has announced the disruption of a large-scale malware-signing-as-a-service (MSaaS) operation that exploited its Azure Artifact Signing platform to generate fraudulent code-signing certificates... The group allegedly abused Microsoft's Artifact Signing service to create short-lived digital certificates that allowed malware to appear legitimate to both users and operating systems.
“9,056,196 files ... 3.28 TB ... 160,870 patients ... 4.18 million diagnoses ... 7.6 million unencrypted EHR scans ... SSN, passports, and other personal data. Financial statements, salaries, taxes.”
Rhysida claimed responsibility for the attack, and Berlin authorities stated that the hackers are attempting to extort a ransom.
Impact T1490 Inhibit System Recovery It executes uses vssadmin to remove volume shadow copies
44 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
108 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation that claims to exfiltrate sensitive data and extorts victims by demanding payment in exchange for withholding publication of the stolen material. In the Berlin incident, it claimed theft of up to 5.79 TB of administrative data and demanded 30 Bitcoin.
A ransomware operation that conducts data theft and extortion, publishing victim listings and claimed stolen data on its leak site. In this incident, it allegedly exfiltrated extensive Berlin state-administration data, including credentials, personnel, financial, legal, and infrastructure-related records.
Financially motivated ransomware operation active since at least May 2023. It typically exfiltrates victim data, encrypts systems, and demands cryptocurrency payments; in this incident it claimed to have stolen Berlin government data and offered it for auction.
Double-extortion ransomware operation that steals victim data and uses threatened publication—here including alleged GDPR-related exposure—as leverage for payment. The article states it has been active since mid-2023.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.