Rhysida is an active ransomware-as-a-service operation first observed in May 2023. It conducts financially motivated double-extortion attacks, typically exfiltrating victim data and threatening publication while also deploying ransomware to encrypt affected systems. Rhysida has targeted government and public-administration bodies, healthcare organizations, educational institutions, critical services, and commercial enterprises internationally. Microsoft tracks a Rhysida-associated threat cluster as Vanilla Tempest.
Early Windows Rhysida payloads use AES-256 in CTR mode for file encryption and protect per-file encryption material using RSA-4096 OAEP. They use partial encryption for large files to accelerate impact, append a Rhysida-specific extension to encrypted files, and create a ransom note. Documented payload options include encryption of a selected directory, self-removal, creation of a SYSTEM scheduled task, and suppression of desktop-background changes. Reported initial-access methods associated with Rhysida activity include phishing, compromised VPN credentials where MFA is absent, and exploitation of the Zerologon vulnerability. Rhysida incidents have also involved data theft and public leak-site extortion; ransomware deployment may occur after an extended post-compromise phase.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Berlin’s state government confirmed it is dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network. The ransomware group Rhysida claimed responsibility, alleging theft of 5.79 TB of data.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Impact : tentative de déploiement ransomware (T1486), partiellement bloquée avant chiffrement. ... L’article attribue explicitement l’opération à Vice Spider, opérateur de Rhysida.
The Rhysida ransomware-as-a-service (RaaS) operation was first observed in May 2023 and has frequently targeted public institutions and critical services.
The Rhysida and Interlock groups, which are known to attack healthcare and other critical infrastructure, have similar TTPs and encryption binaries, leading to some speculation of a connection between the two groups.
US government agencies released an advisory note on Rhysida last week, stating that the “emerging ransomware variant” had been deployed against the education, manufacturing, IT and government sectors since May.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The Broomstick/Oyster chain "created persistence through a scheduled task called: AlphaSecurity"; Rhysida also supports "-S create a scheduled task running as SYSTEM."
Vanilla Tempest submitted "trojanized Microsoft Teams installers," distributed through legitimate advertising and fraudulent download pages; IBM documented "MSteamsV7.80.exe."
The impact-stage correlation includes "event log clearing" alongside shadow deletion and mass file modification.
« Impact : tentative de déploiement ransomware (T1486), partiellement bloquée avant chiffrement »
The recommended high-confidence impact correlation includes "vssadmin / shadow deletion."
65 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
119 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Double-extortion ransomware operation using a Tor leak site and Bitcoin demands. A flaw in its encryption random-number generator enabled a free decryptor for affected earlier variants.
Ransomware operation associated with data theft, extortion, leak-site publication, and intended file encryption. In this incident, encryption was partially prevented, but approximately 1.44 million files were reportedly published after exfiltration.
Ransomware-/Erpressungsoperation, die sich zum Angriff auf zwei Berliner Senatsverwaltungen bekannte, die Exfiltration von 5,7 TB Daten behauptete und gestohlene Daten zum Verkauf anbot beziehungsweise nach Ablauf eines Ultimatums veröffentlichte.
Ransomware operation responsible for the attack on Berlin's state network. In this incident it allegedly exfiltrated approximately 5.79 TB across 1.44 million files, demanded a ransom, and published stolen data—including a later package reportedly containing access credentials—after Berlin declined to pay.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.