Rhysida is a ransomware family and ransomware-as-a-service operation that emerged in 2023 and has been used in double-extortion attacks against organizations worldwide. The malware encrypts victim systems while operators or affiliates also steal data and threaten to leak or sell it to increase pressure for payment. Rhysida has been associated with attacks affecting healthcare, education, government, manufacturing, information technology, and other critical sectors, with multiple high-profile incidents involving operational disruption and exposure of sensitive personal or organizational data.
Rhysida intrusions have been linked to opportunistic targeting as well as affiliate-driven campaigns. Reported initial access methods include phishing and compromise of external remote access services, including VPN access obtained with stolen or valid credentials. Public reporting also associates Rhysida activity with exploitation of exposed services and, in some cases, use of known vulnerabilities such as Zerologon in broader attack chains. Deployment has been observed via Cobalt Strike or similar post-exploitation frameworks, and some reporting links the ecosystem around Rhysida to signed malware delivery chains that abuse fraudulent code-signing services to reduce security friction.
On execution, Rhysida traverses files on local systems and drops PDF ransom notes instructing victims to contact the operators through a Tor-based portal using a unique identifier. The operation commonly demands cryptocurrency and follows a multi-extortion model in which stolen data is advertised, auctioned, or leaked if negotiations fail. Rhysida has been described as an emerging but tactically diverse ransomware threat, and some analyses note similarities or possible lineage connections with Vice Society or related affiliate activity. The exact identity of the operators remains unconfirmed, although the operation is widely treated as a financially motivated criminal enterprise rather than a state-directed campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
An advisory note from the FBI and the US Cybersecurity and Information Structure Agency (CISA) last week said the malware, first identified in May 2023, is offered as ransomware as a service to criminal groups, which then share profits with the ransomware owners. | Criminals typically gain access to infected computer systems by using known vulnerabilities, such as ZeroLogon.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Rhysida and Interlock groups, which are known to attack healthcare and other critical infrastructure, have similar TTPs and encryption binaries, leading to some speculation of a connection between the two groups.
Vice Society was observed deploying INC ransomware against the health care industry; this group has a long-standing habit of cycling through third-party payloads such as BlackCat, Rhysida, Hello Kitty, Zeppelin, and Quantum Locker.
US government agencies released an advisory note on Rhysida last week, stating that the “emerging ransomware variant” had been deployed against the education, manufacturing, IT and government sectors since May.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Attackers then distributed the signed malware through tactics such as search manipulation and malicious ads, where users are more likely to trust what they encounter.
Further analysis revealed that Fox Tempest expanded its offerings earlier this year by providing customers with pre-configured virtual machines hosted through Cloudzy infrastructure. Users could upload malware to these systems and receive digitally signed binaries generated through certificates controlled by the group.
Attackers have also compromised credentials to access virtual private networks (VPNs), particularly where organisations have failed to enable two-factor authentication by default.
Attackers have also compromised credentials to access virtual private networks (VPNs), particularly where organisations have failed to enable two-factor authentication by default.
The signed files often impersonated trusted software brands such as Microsoft Teams, AnyDesk, PuTTY, and Webex, making them appear more credible to potential victims.
Microsoft has announced the disruption of a large-scale malware-signing-as-a-service (MSaaS) operation that exploited its Azure Artifact Signing platform to generate fraudulent code-signing certificates... The group allegedly abused Microsoft's Artifact Signing service to create short-lived digital certificates that allowed malware to appear legitimate to both users and operating systems.
Rhysida said it stole the personal records of 100,000 people. To prove its claim, the ransomware group posted sample images of what it says are documents stolen from Spindletop.
The library confirmed that personal data stolen in a cyber-attack last month has appeared for sale online.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
88 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an example of malware associated with abuse of code-signing certificates.
Named ransomware family referenced as one of the third-party payloads used by Vice Society.
Ransomware deployed via Fox Tempest's malware-signing-as-a-service operation; signed binaries helped it masquerade as legitimate software and evade security controls.
Ransomware payload whose malicious files were signed via the Fox Tempest service to appear legitimate and evade security controls.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.