Rhysida is a ransomware-as-a-service operation first observed in May 2023 that conducts double-extortion attacks, combining file encryption with theft and threatened publication of stolen data. The group has rapidly established itself as an active ransomware actor with victims across North America, Europe, South America, and Australia. Reported victims include organizations in healthcare, government, education, manufacturing, technology, managed services, and construction. High-profile targeting has included the British Library, the Chilean Army, healthcare delivery organizations, and public-sector entities. Rhysida commonly gains initial access through phishing and then uses post-compromise tooling such as PowerShell, Cobalt Strike, and PsExec to expand access and prepare systems for ransomware deployment. Observed behavior includes terminating security tools, deleting shadow copies, modifying RDP settings, clearing Windows event logs, and using scheduled tasks for execution or persistence. Rhysida has also been associated with Active Directory discovery and broader hands-on-keyboard post-exploitation activity. Its ransomware uses LibTomCrypt components, generates per-file encryption material via a ChaCha20-based pseudorandom process, encrypts files with AES-CTR, and protects key material with an embedded 4096-bit RSA public key. The operation maintains a leak site and publicly pressures victims by threatening release of exfiltrated data. The group has shown a notable concentration on education and has also been specifically warned on by U.S. authorities for increased attacks against healthcare and public health organizations. Multiple assessments have linked Rhysida to Vice Society, with some researchers judging that Rhysida may represent a rebrand, successor, or closely related cluster, although that relationship is not definitively resolved. Rhysida has also been observed using abused or fraudulently obtained code-signing certificates in support of its operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
71 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack and associated data breach against Pierce Township, with stolen data including judicial materials, employee PII, legal settlements, financial records, and internal email archives.
Conducting a ransomware attack and data breach against SIA Medical Centre, with stolen medical, HR, legal, financial, and credential data advertised.
Mentioned only as connected background context to Interlock.
Ransomware group observed using malware signed through Fox Tempest's illicit signing service.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.