Rhysida is a financially motivated ransomware-as-a-service operation that emerged in May 2023. Also known as the Rhysida ransomware group or gang, it encompasses operators and affiliates conducting ransomware and data-extortion intrusions. Its targets span healthcare, government, education, manufacturing, technology, legal services, real estate management, and entertainment. Its country of origin is not established with high confidence. Rhysida conducts double extortion by stealing data before encrypting victim systems and threatening publication. It maintains a dedicated leak site, offers stolen data for auction, and publishes information when victims refuse payment. It also conducts data-theft extortion without confirmed encryption, including the August 2026 compromise of two Berlin Senate administrations. Other prominent activity includes the December 2023 attack against Insomniac Games, which exposed proprietary game-development material. Initial-access methods include phishing, compromised VPN credentials, purchased VPN and RDP access, exploitation of external remote services, and Zerologon exploitation (CVE-2020-1472). An investigated intrusion used SEO poisoning to distribute a trojanized PuTTY application that established access and persistence. Operators have used RDP for lateral movement, Advanced Port Scanner for network enumeration, and AzCopy to exfiltrate files to attacker-controlled Azure storage. Pre-encryption activity includes security-service and process termination, antivirus tampering, local-account modification, enabling remote administration, deleting backups and shadow copies, disabling recovery, and clearing event logs and PowerShell history. A weakness in the random-number generation of earlier Rhysida ransomware variants enabled a free decryptor; this does not establish decryptability of newer variants.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
78 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reportedly conducted a ransomware attack against US professional-services firm Gress Clark Young & Schoepper, discovered on October 10, 2026. The report describes a breach involving 167,804 files totaling approximately 166.4 GB, including financial records, client identity information, medical records, internal case-management documents, and court e-filing credentials. The content does not establish the initial access method or independently verify the breach claims.
The report attributes a ransomware attack against Anne Arundel County, Maryland, to Rhysida, with the breach reportedly discovered on October 9, 2026. It describes 814,500 files totaling 2.6 TB, including sensitive identity documents, medical and methadone-clinic records, payroll and personnel information, and jail intelligence files. The content does not establish the initial access method or identify a specific malware family.
Rhysida claims to have stolen 814,500 files totaling 2.6 TB from Anne Arundel County, Maryland, which was listed on the leak site on October 9, 2026. The claimed dataset includes sensitive medical and methadone-clinic records, identity documents, payroll and personnel records, and jail gang intelligence; no ransom amount or deadline is stated.
Reportedly conducted a ransomware attack against RealManage, a US community association management company. The incident report describes 1.84 TB of exposed data, including homeowner and vendor Social Security numbers, banking details, tax records, debt information, property documents, and SQL Server databases. Discovery is listed as October 9, 2026, at 12:10 UTC; the content provides no independent verification of the attribution or data volume.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.