Rhysida is a ransomware family and financially motivated ransomware-as-a-service operation first observed in May 2023. Its operators use double extortion, stealing information before encrypting systems and threatening to publish stolen data unless victims pay. Rhysida targets organizations worldwide, particularly healthcare, education, government, manufacturing, and critical services. Notable victims include the British Library and Insomniac Games. Associated activity has been linked to Vanilla Tempest, also tracked as VICE SPIDER and GOLD VICTOR, a threat actor associated with Vice Society.
Early Rhysida payloads are Windows executables compiled with MinGW and use LibTomCrypt for cryptographic operations. They encrypt file data with AES-256 in CTR mode and protect per-file keys and initialization vectors with RSA-4096 OAEP. Partial encryption of large files reduces execution time while increasing operational impact. Supported execution options include encrypting a selected directory, self-removal, and creating a scheduled task running as SYSTEM. A weakness in the random-number generation of earlier variants enabled a free decryptor; this does not establish decryptability of newer variants.
Rhysida-associated intrusions have used phishing, compromised VPN credentials on accounts lacking multifactor authentication, purchased remote-access accounts, and exploitation of Zerologon (CVE-2020-1472). Other documented delivery chains involve SEO poisoning and malicious advertisements distributing trojanized software installers. Associated campaigns have also used fake CAPTCHA and TerminalFix lures to induce execution of malicious commands. During intrusions, operators use remote desktop access for lateral movement, network enumeration tools for discovery, and AzCopy to exfiltrate data to attacker-controlled cloud storage. Pre-encryption activity has included attempts to disable security products, terminate application and backup processes, delete backups and shadow copies, disable recovery, and erase event logs and command histories. These intrusion-stage behaviors involve supporting tools and scripts rather than necessarily being implemented within the ransomware executable.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In other cases, the group exploited vulnerabilities such as Zerologon, a privilege escalation flaw in Netlogon Remote Protocol (CVE-2020-1472). | The Rhysida group has been observed using compromised valid VPN credentials to gain initial access to their victims, notably due to accounts lacking MFA.
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Rhysida group has been observed using compromised valid VPN credentials to gain initial access to their victims, notably due to accounts lacking MFA.
This group has been linked to the Vice Society and Rhysida ransomware families.
This group has been linked to the Vice Society and Rhysida ransomware families.
This group has been linked to the Vice Society and Rhysida ransomware families.
The Rhysida and Interlock groups, which are known to attack healthcare and other critical infrastructure, have similar TTPs and encryption binaries, leading to some speculation of a connection between the two groups.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The Broomstick/Oyster chain "created persistence through a scheduled task called: AlphaSecurity"; Rhysida also supports "-S create a scheduled task running as SYSTEM."
Vanilla Tempest submitted "trojanized Microsoft Teams installers," distributed through legitimate advertising and fraudulent download pages; IBM documented "MSteamsV7.80.exe."
"Berlin’s state government has launched a major review after ransomware attackers published data stolen from two government departments."
The recommended high-confidence impact correlation includes "vssadmin / shadow deletion."
65 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
125 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware associated with the December 2023 attack targeting Sony and Insomniac. The attack reportedly resulted in 1.7 TB of stolen data, including an early Wolverine build and source code subsequently used to develop an unofficial PC port. The article does not describe the malware's technical behavior.
Rhysida is identified as the ransomware group responsible for the reported attack against clicks digital GmbH.
Ransomware family mentioned as background to the attribution of Lorem Ipsum Loader to Rapid Brigantine, also tracked as GOLD VICTOR. The content does not report its deployment in STAC4924; Sophos observed no encryption in that campaign.
Double-extortion ransomware operation using a Tor leak site and Bitcoin demands. A flaw in its encryption random-number generator enabled a free decryptor for affected earlier variants.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.