Discovery Enum
- PowerView
Rhysida is a ransomware family and ransomware-as-a-service operation first observed in 2023.
Profile source: Mallory opens in a new tabRhysida
Rhysida is a ransomware family and ransomware-as-a-service operation first observed in 2023. It is used in double-extortion attacks that combine file encryption with data theft, with operators or affiliates demanding payment both for decryption and for withholding stolen information from publication or sale. The malware and its operators have been linked to intrusions affecting organizations in education, healthcare, manufacturing, information technology, government, and other critical sectors, with multiple high-profile incidents involving operational disruption and public data-leak extortion.
Rhysida intrusions commonly rely on phishing and compromise of external remote access services, including use of valid credentials to access internal VPN environments. Reporting also associates Rhysida activity with exploitation of exposed services and, in some cases, use of Cobalt Strike or similar post-exploitation frameworks during deployment. The group has been described as opportunistic in victim selection, although healthcare and other critical infrastructure organizations have been repeatedly affected.
Once inside a network, Rhysida operators conduct post-compromise activity consistent with mature ransomware operations, including use of living-off-the-land techniques, credential abuse, and broad hands-on-keyboard activity before encryption. The ransomware traverses local files, encrypts victim data, and drops PDF ransom notes instructing victims to communicate through a Tor-based portal using a unique identifier. Rhysida campaigns are also associated with theft and leak-site publication of victim data, making exfiltration a core part of the extortion model.
Rhysida has been connected by multiple researchers to the Vice Society or Gold Victor criminal ecosystem, with some assessments suggesting a rebrand or operational continuity between those clusters. It has also been used by affiliates or actors such as Vanilla Tempest, and has appeared alongside broader cybercrime tooling and services including abused code-signing infrastructure intended to improve malware delivery and defense evasion. Security reporting has noted tactical breadth across Rhysida operations relative to many peer ransomware groups.
f6e5f0ed974c89e2b4a47989fc987c796742fdde9d5fde37ac5a9c9cbb1f691f7cfba113342f78b5909f606c26fc1dc46dd8c26f64df37d0c7645b63c9bba51f0cf5491278c7d87e8c3fc88c7f9f26ffd86383882515b7a9218d5f69924feadf3225b95fc72f238ab1e53bfabc11b551ddaa09b5c3bf5aa24e300c24905469f25f3ecd02a94cec2b62bfecd79f5a1d981888ecf4e90f02ecaaefdb3624825fa2Reported operators
The Rhysida and Interlock groups, which are known to attack healthcare and other critical infrastructure, have similar TTPs and encryption binaries, leading to some speculation of a connection between the two groups.
Vice Society was observed deploying INC ransomware against the health care industry; this group has a long-standing habit of cycling through third-party payloads such as BlackCat, Rhysida, Hello Kitty, Zeppelin, and Quantum Locker.
US government agencies released an advisory note on Rhysida last week, stating that the “emerging ransomware variant” had been deployed against the education, manufacturing, IT and government sectors since May.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Rhysida is a cybercriminal group that first surfaced in May 2023. Its ransomware can steal data and lock down targeted systems. It then demands a ransom both for deleting stolen data and for a key to restore infected devices. Rhysida operates a ransomware-as-a-service business in which affiliates pay Rhysida to use its malware and infrastructure to launch attacks and collect ransoms.
OysterLoader, also tracked as Broomstick and CleanUp, is a multi-stage loader malware written in C++ and actively leveraged in campaigns linked to the Rhysida ransomware group.
Scattered Spider... aka possibly sometimes BlackCatALPHV or Rhysida... Rhysida (New in Top Variants).
"...the same threat actor deploying Rhysida ransomware against two different organizations..."
X-Force links the group to malware developers/operators such as Broomstick, Supper, PortStarter, SystemBC, and Rhysida ransomware...
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.