Rhysida is a ransomware family and ransomware-as-a-service operation first observed in May 2023 that rapidly established itself through double-extortion attacks against organizations in education, government, manufacturing, technology, managed service providers, and especially healthcare and public health. Victims have been reported across North America, South America, Western Europe, Australia, and elsewhere, and notable incidents have included attacks on the British Library, the Chilean Army, healthcare delivery organizations, and energy-sector entities. Multiple assessments have suggested a possible relationship to Vice Society based on overlapping victimology and operational patterns, but that linkage remains unconfirmed.
Rhysida operators commonly obtain initial access through phishing and then use post-compromise tooling such as Cobalt Strike, PowerShell, and PsExec to expand access and deploy the locker. Observed pre-encryption activity includes terminating security tools, deleting shadow copies, modifying remote desktop settings, clearing Windows event logs, and changing Active Directory credentials. The malware and associated scripts have also been used for lateral movement and broader post-exploitation activity prior to encryption.
The ransomware encrypts files while excluding selected directories and file types to preserve system operability. Reporting consistently associates Rhysida with ChaCha20 and RSA-based cryptography, while more detailed reverse engineering has shown implementations using LibTomCrypt pseudorandom generation for per-file material and AES-CTR file encryption with RSA protection of keys and initialization vectors. Rhysida appends its own extension to encrypted files, drops a ransom note presented as a message from a purported cybersecurity team, and changes the victim desktop wallpaper. The operation is known for exfiltrating data and threatening publication on a leak site if payment is not made.
Rhysida’s locker was initially assessed as technically immature relative to its operational impact, with some defensive and destructive actions handled by external scripts rather than the core binary. Later analysis nevertheless showed rapid evolution in tradecraft. A significant implementation flaw in its encryption process enabled researchers to develop a decryptor, making Rhysida one of the relatively rare modern ransomware families for which public decryption became possible under some circumstances.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
An advisory note from the FBI and the US Cybersecurity and Information Structure Agency (CISA) last week said the malware, first identified in May 2023, is offered as ransomware as a service to criminal groups, which then share profits with the ransomware owners. | Criminals typically gain access to infected computer systems by using known vulnerabilities, such as ZeroLogon.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Files encrypted by Rhysida ransomware can be successfully decrypted, due to a implementation vulnerability discovered by Korean researchers and leveraged to create a decryptor. Rhysida is a relatively new ransomware-as-a-service gang that engages in double extortion.
The Rhysida and Interlock groups, which are known to attack healthcare and other critical infrastructure, have similar TTPs and encryption binaries, leading to some speculation of a connection between the two groups.
US government agencies released an advisory note on Rhysida last week, stating that the “emerging ransomware variant” had been deployed against the education, manufacturing, IT and government sectors since May.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Attackers then distributed the signed malware through tactics such as search manipulation and malicious ads, where users are more likely to trust what they encounter.
Further analysis revealed that Fox Tempest expanded its offerings earlier this year by providing customers with pre-configured virtual machines hosted through Cloudzy infrastructure. Users could upload malware to these systems and receive digitally signed binaries generated through certificates controlled by the group.
Attackers have also compromised credentials to access virtual private networks (VPNs), particularly where organisations have failed to enable two-factor authentication by default.
Attackers have also compromised credentials to access virtual private networks (VPNs), particularly where organisations have failed to enable two-factor authentication by default.
Persistence T1053.005 Scheduled Task/Job: Scheduled Task When executed with the argument -S, it will create a scheduled task named Rhsd that will execute the ransomware
Execution T1059.001 Command and Scripting Interpreter: PowerShell It uses PowerShell to create scheduled task named Rhsd pointing to the ransomware.
Persistence T1053.005 Scheduled Task/Job: Scheduled Task When executed with the argument -S, it will create a scheduled task named Rhsd that will execute the ransomware
The signed files often impersonated trusted software brands such as Microsoft Teams, AnyDesk, PuTTY, and Webex, making them appear more credible to potential victims.
T1070.001 Indicator Removal: Clear Windows Event Logs It uses wevtutil.exe to clear Windows event logs.
Defense Evasion T1070.004 Indicator Removal: File Deletion Rhysida ransomware deletes itself after execution. The scheduled task (Rhsd) created would also be deleted after execution.
Microsoft has announced the disruption of a large-scale malware-signing-as-a-service (MSaaS) operation that exploited its Azure Artifact Signing platform to generate fraudulent code-signing certificates... The group allegedly abused Microsoft's Artifact Signing service to create short-lived digital certificates that allowed malware to appear legitimate to both users and operating systems.
Rhysida said it stole the personal records of 100,000 people. To prove its claim, the ransomware group posted sample images of what it says are documents stolen from Spindletop.
An organic relationship between the #Rhysida and #ViceSociety ransomware teams?
Impact T1490 Inhibit System Recovery It executes uses vssadmin to remove volume shadow copies
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
102 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family mentioned only in connection/comparison with Interlock.
Ransomware family referenced in reporting involving BitLaunch-hosted infrastructure.
Mentioned only as an example of malware associated with abuse of code-signing certificates.
Named ransomware family referenced as one of the third-party payloads used by Vice Society.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.