Discovery Enum
- PowerView
Rhysida is a ransomware-as-a-service operation active since May 2023.
Profile source: Mallory opens in a new tabRhysida
Rhysida is a ransomware-as-a-service operation active since May 2023. It conducts double-extortion attacks, stealing victim data and encrypting systems before demanding cryptocurrency payments and threatening public disclosure. Victims have included government entities, healthcare and public-health organizations, educational institutions, manufacturers, technology companies, managed service providers, the British Library, the Chilean Army, and Holding Slovenske Elektrarne. Activity has been reported across Western Europe, the Americas, Australia, and other regions.
Rhysida commonly obtains initial access through phishing; U.S. government guidance also identifies compromised VPN credentials lacking multifactor authentication and exploitation of the Zerologon vulnerability as observed access methods. Operators have used Cobalt Strike, PsExec, and PowerShell tooling to deploy payloads, impair endpoint defenses, remove shadow copies, alter Remote Desktop Protocol settings, and clear Windows event logs. The ransomware can establish scheduled-task persistence and change the desktop wallpaper to display its extortion message.
The locker encrypts eligible files using AES in CTR mode with per-file keying material generated through LibTomCrypt's ChaCha20 pseudorandom-number generator and protected using an embedded 4096-bit RSA public key. A publicly reported implementation weakness in the ransomware's time-seeded random-number generation enabled researchers to develop a decryptor for affected files. Rhysida's operators and precise geographic origin remain unconfirmed; an asserted connection to Vice Society is not established conclusively.
f6e5f0ed974c89e2b4a47989fc987c796742fdde9d5fde37ac5a9c9cbb1f691f7cfba113342f78b5909f606c26fc1dc46dd8c26f64df37d0c7645b63c9bba51f0cf5491278c7d87e8c3fc88c7f9f26ffd86383882515b7a9218d5f69924feadf3225b95fc72f238ab1e53bfabc11b551ddaa09b5c3bf5aa24e300c24905469f25f3ecd02a94cec2b62bfecd79f5a1d981888ecf4e90f02ecaaefdb3624825fa2Reported operators
Files encrypted by Rhysida ransomware can be successfully decrypted, due to a implementation vulnerability discovered by Korean researchers and leveraged to create a decryptor. Rhysida is a relatively new ransomware-as-a-service gang that engages in double extortion.
The Rhysida and Interlock groups, which are known to attack healthcare and other critical infrastructure, have similar TTPs and encryption binaries, leading to some speculation of a connection between the two groups.
US government agencies released an advisory note on Rhysida last week, stating that the “emerging ransomware variant” had been deployed against the education, manufacturing, IT and government sectors since May.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Rhysida is a cybercriminal group that first surfaced in May 2023. Its ransomware can steal data and lock down targeted systems. It then demands a ransom both for deleting stolen data and for a key to restore infected devices. Rhysida operates a ransomware-as-a-service business in which affiliates pay Rhysida to use its malware and infrastructure to launch attacks and collect ransoms.
OysterLoader, also tracked as Broomstick and CleanUp, is a multi-stage loader malware written in C++ and actively leveraged in campaigns linked to the Rhysida ransomware group.
Scattered Spider... aka possibly sometimes BlackCatALPHV or Rhysida... Rhysida (New in Top Variants).
"...the same threat actor deploying Rhysida ransomware against two different organizations..."
X-Force links the group to malware developers/operators such as Broomstick, Supper, PortStarter, SystemBC, and Rhysida ransomware...
Exploited software
MITRE ATT&CK
Reporting
The Rhysida ransomware operation has intensified its focus on healthcare, with reporting and government guidance describing an expanding threat that has hit organizations across Western Europe, the Americas, and Australia. U.S. health-sector alerts and vendor research say the group has targeted education, government, manufacturing, technology, managed service providers, and increasingly healthcare and public health entities. Researchers have also linked Rhysida to tactics associated with the defunct Vice Society operation, while earlier incidents included the leak of stolen documents from the Chilean Army and suspected involvement in disruptive attacks on medical providers. Security reporting says Rhysida commonly gains initial access through phishing and then uses tools such as Cobalt Strike and PowerShell to disable defenses, delete shadow copies, alter RDP settings, and deploy ransomware. In a newly reported healthcare case, SIA Medical Centre was listed as a victim, with the attackers claiming theft of roughly 20,000 patient medical records along with staff identity documents, plaintext credentials, HR files, and legal and financial records. The allegedly exposed data included names, dates of birth, Medicare numbers, clinical notes, insurance files, passports, driver’s licenses, and login credentials, underscoring the group’s dual risk of operational disruption and large-scale sensitive data exposure in the health sector.
Splunk has removed two Windows discovery analytics from its Threat Research content library and replaced them with updated detections for attacker use of built-in net commands to enumerate users and groups. The deprecated rules, Local Account Discovery with Net and Net Localgroup Discovery, identified execution of net.exe or net1.exe with arguments such as user, users, and localgroup, activity commonly used to list local accounts and group memberships on compromised hosts. The changes align with well-documented adversary behavior in MITRE ATT&CK techniques T1087.001 and T1069.001, where threat actors use commands like net user, net user /domain, and net localgroup administrators to gather account and privilege information that can support privilege escalation and lateral movement. Splunk said the removed analytics were deprecated in version 5.2.0 in favor of Windows User Discovery Via Net and Windows Group Discovery Via Net, with the original detections having relied on EDR process telemetry, Sysmon Event ID 1, Windows Security Event ID 4688, and related endpoint data sources.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.