Skip to content

Rhysida

Rhysida is a ransomware-as-a-service operation active since May 2023.

Profile source: Mallory opens in a new tab

Rhysida

Family profile

Rhysida is a ransomware-as-a-service operation active since May 2023. It conducts double-extortion attacks, stealing victim data and encrypting systems before demanding cryptocurrency payments and threatening public disclosure. Victims have included government entities, healthcare and public-health organizations, educational institutions, manufacturers, technology companies, managed service providers, the British Library, the Chilean Army, and Holding Slovenske Elektrarne. Activity has been reported across Western Europe, the Americas, Australia, and other regions.

Rhysida commonly obtains initial access through phishing; U.S. government guidance also identifies compromised VPN credentials lacking multifactor authentication and exploitation of the Zerologon vulnerability as observed access methods. Operators have used Cobalt Strike, PsExec, and PowerShell tooling to deploy payloads, impair endpoint defenses, remove shadow copies, alter Remote Desktop Protocol settings, and clear Windows event logs. The ransomware can establish scheduled-task persistence and change the desktop wallpaper to display its extortion message.

The locker encrypts eligible files using AES in CTR mode with per-file keying material generated through LibTomCrypt's ChaCha20 pseudorandom-number generator and protected using an embedded 4096-bit RSA public key. A publicly reported implementation weakness in the ransomware's time-seeded random-number generation enabled researchers to develop a decryptor for affected files. Rhysida's operators and precise geographic origin remain unconfirmed; an asserted connection to Vice Society is not established conclusively.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence

Operational record

28
Indicators
1
YARA rules
1
Ransom notes
2
Leak sites
2 available

Discovery Enum

  • PowerView

Exfiltration

  • WinSCP

LOLBAS

  • NTDS Utility (ntdsutil)
  • PsExec
  • WMIC
  • Windows Event Utility (wevtutil)

Offsec

  • Impacket

RMM Tools

  • AnyDesk

Published indicators

Md5

28 total
  • f6e5f0ed974c89e2b4a47989fc987c79
  • 6742fdde9d5fde37ac5a9c9cbb1f691f
  • 7cfba113342f78b5909f606c26fc1dc4
  • 6dd8c26f64df37d0c7645b63c9bba51f
  • 0cf5491278c7d87e8c3fc88c7f9f26ff
  • d86383882515b7a9218d5f69924feadf
  • 3225b95fc72f238ab1e53bfabc11b551
  • ddaa09b5c3bf5aa24e300c24905469f2
  • 5f3ecd02a94cec2b62bfecd79f5a1d98
  • 1888ecf4e90f02ecaaefdb3624825fa2

Recent claims

Reported operators

Threat actors

11 named in public reporting
Vanilla Tempest

Files encrypted by Rhysida ransomware can be successfully decrypted, due to a implementation vulnerability discovered by Korean researchers and leveraged to create a decryptor. Rhysida is a relatively new ransomware-as-a-service gang that engages in double extortion.

KongTuke

The Rhysida and Interlock groups, which are known to attack healthcare and other critical infrastructure, have similar TTPs and encryption binaries, leading to some speculation of a connection between the two groups.

Gold Victor

US government agencies released an advisory note on Rhysida last week, stating that the “emerging ransomware variant” had been deployed against the education, manufacturing, IT and government sectors since May.

Storm-0501

Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.

Storm-0249

Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.

Storm 2561

Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.

Rhysida

Rhysida is a cybercriminal group that first surfaced in May 2023. Its ransomware can steal data and lock down targeted systems. It then demands a ransom both for deleting stolen data and for a key to restore infected devices. Rhysida operates a ransomware-as-a-service business in which affiliates pay Rhysida to use its malware and infrastructure to launch attacks and collect ransoms.

WIZARD SPIDER

OysterLoader, also tracked as Broomstick and CleanUp, is a multi-stage loader malware written in C++ and actively leveraged in campaigns linked to the Rhysida ransomware group.

Scattered Spider

Scattered Spider... aka possibly sometimes BlackCatALPHV or Rhysida... Rhysida (New in Top Variants).

TAC5279

"...the same threat actor deploying Rhysida ransomware against two different organizations..."

Hive0163

X-Force links the group to malware developers/operators such as Broomstick, Supper, PortStarter, SystemBC, and Rhysida ransomware...

Exploited software

Vulnerabilities linked to Rhysida

1 CVEs

MITRE ATT&CK

Rhysida in ATT&CK

58 distinct techniques

Techniques

58 techniques
T1567 Exfiltration Over Web Service T1486 Data Encrypted for Impact T1657 Financial Theft T1041 Exfiltration Over C2 Channel T1566 Phishing T1082 System Information Discovery T1491.001 Internal Defacement T1059.003 Windows Command Shell T1070.001 Clear Windows Event Logs T1490 Inhibit System Recovery T1059.001 PowerShell T1070.004 File Deletion T1083 File and Directory Discovery T1053.005 Scheduled Task T1553.002 Code Signing T1036 Masquerading T1587.001 Malware T1204 User Execution T1608.006 SEO Poisoning T1537 Transfer Data to Cloud Account T1583 Acquire Infrastructure T1074 Data Staged T1078 Valid Accounts T1210 Exploitation of Remote Services T1218 System Binary Proxy Execution T1133 External Remote Services T1190 Exploit Public-Facing Application T1068 Exploitation for Privilege Escalation T1048 Exfiltration Over Alternative Protocol T1553 Subvert Trust Controls T1189 Drive-by Compromise T1204.002 Malicious File T1105 Ingress Tool Transfer T1005 Data from Local System T1021.001 Remote Desktop Protocol T1491 Defacement T1489 Service Stop T1195.002 Compromise Software Supply Chain T1548.002 Abusing Elevation Control Mechanism: Bypass User Account Control T1059 Command and Scripting Interpreter T1129 Shared Modules T1547.001 Registry Run Keys / Startup Folder T1055 Process Injection T1055.003 Thread Execution Hijacking T1027 Obfuscated Files or Information T1497 Virtualization/Sandbox Evasion T1564 Hidden Artifacts T1564.004 NTFS File Attributes T1620 Reflective DLL Injection T1010 Application Window Discovery T1057 Process Discovery T1518.001 Security Software Discovery T1119 Automated Collection T1071 Application Layer Protocol T1071.001 Web Protocols T1587 Develop Capabilities T1595 Active Scanning T1598 Phishing for Information

Reporting

Research mentioning Rhysida

Aug 13
Hookphish

Ransomware Group rhysida Hits: SIA Medical Centre

The Rhysida ransomware operation has intensified its focus on healthcare, with reporting and government guidance describing an expanding threat that has hit organizations across Western Europe, the Americas, and Australia. U.S. health-sector alerts and vendor research say the group has targeted education, government, manufacturing, technology, managed service providers, and increasingly healthcare and public health entities. Researchers have also linked Rhysida to tactics associated with the defunct Vice Society operation, while earlier incidents included the leak of stolen documents from the Chilean Army and suspected involvement in disruptive attacks on medical providers. Security reporting says Rhysida commonly gains initial access through phishing and then uses tools such as Cobalt Strike and PowerShell to disable defenses, delete shadow copies, alter RDP settings, and deploy ransomware. In a newly reported healthcare case, SIA Medical Centre was listed as a victim, with the attackers claiming theft of roughly 20,000 patient medical records along with staff identity documents, plaintext credentials, HR files, and legal and financial records. The allegedly exposed data included names, dates of birth, Medicare numbers, clinical notes, insurance files, passports, driver’s licenses, and login credentials, underscoring the group’s dual risk of operational disruption and large-scale sensitive data exposure in the health sector.

May 13
Splunk Research

Detection: Net Localgroup Discovery | Splunk Security Content

Splunk has removed two Windows discovery analytics from its Threat Research content library and replaced them with updated detections for attacker use of built-in net commands to enumerate users and groups. The deprecated rules, Local Account Discovery with Net and Net Localgroup Discovery, identified execution of net.exe or net1.exe with arguments such as user, users, and localgroup, activity commonly used to list local accounts and group memberships on compromised hosts. The changes align with well-documented adversary behavior in MITRE ATT&CK techniques T1087.001 and T1069.001, where threat actors use commands like net user, net user /domain, and net localgroup administrators to gather account and privilege information that can support privilege escalation and lateral movement. Splunk said the removed analytics were deprecated in version 5.2.0 in favor of Windows User Discovery Via Net and Windows Group Discovery Via Net, with the original detections having relied on EDR process telemetry, Sysmon Event ID 1, Windows Security Event ID 4688, and related endpoint data sources.

May 13
Splunk Research

Detection: Local Account Discovery with Net | Splunk Security Content

Aug 9
Bleeping Computer

Rhysida ransomware behind recent attacks on healthcare

Aug 9
Trend Micro Research

An Overview of the New Rhysida Ransomware | Trend Micro (US)

Aug 8
Talosintelligence Other

What Cisco Talos knows about the Rhysida ransomware

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.