Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors rhysida

Description

Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks and Cobalt Strike to breach the targets' networks and deploy their payloads.<br> <br> The group threatens to publicly distribute exfiltrated data if the ransom is not paid, and it's worth mentioning that Rhysida is still in the early stages of development.<br> <br> The ransomware leaves PDF notes in the affected folders, instructing victims to contact the group through its portal, and payment is made via Bitcoin.<br> <br> After encryption, the ransomware appends the extension '.ryshida' to encrypted files.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs Known victims: 269 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Rhysida, a ransomware-as-a-service (RAAS) group emerged in May 2023, utilizing phishing and Cobalt Strike for network breaches. Their campaigns target various sectors globally, leaving '.ryshida' file extensions and demanding Bitcoin ransoms, with threats of data distribution as leverage.

Goals & Targeting

Rhysida's primary goal is financial gain. Their targeting strategy focuses on maximizing profit through widespread campaigns rather than sector-specific attacks. victims include educational institutions, healthcare providers, and corporate entities in various countries, with a preference for easy compromise targets.

Enhanced Description

Rhysida is a mid-tier ransomware operation that leverages phishing emails to distribute their malware, which requires Cobalt Strike for initial breach execution. Once deployed, the rhysida ransomware encrypts files and appends '.ryshida' extensions. Victims are instructed to contact via a portal for decryption keys. Ransoms are paid in Bitcoin, with the group threatening data leaks if payments aren't made. Since their emergence, they have targeted organizations across multiple sectors including education, healthcare, and local government.

Key Capabilities

  • Phishing via spear-phishing emails
  • Cobalt Strike for initial access and lateral movement
  • Ransomware deployment with '.ryshida' file extension
  • Data exfiltration for ransom leverage
  • Bitcoin-based payment mechanism

MITRE ATT&CK Tactics

Exfiltration of Data for Impact
Ransomware Deployment

ATT&CK Techniques

T1059.003 - Spear-phishing with attachment
T1003 -Credential dumping via Registry tools
T1566.001 - PupyRTM for persistence

Software / Tooling

Cobalt Strike
rhysida Ransomware

Campaigns & Victims

Rhysida has carried out numerous campaigns across North America and Europe, targeting sectors like education and healthcare. Their recent operations include attacks against Stelia North America and Southold Town Senior Services, indicating a preference for critical infrastructure and organizations with less robust defenses.

IOC Patterns

  • Malicious hashes identified from MD5 samples
  • Network communication patterns indicative of Cobalt Strike activity
  • Spear-phishing emails with malicious attachments

Recommended Actions

  • Implement advanced email filtering solutions to detect phishing attempts.
  • Monitor for Cobalt Strike-related network behaviors and signatures.
  • Enhance endpoint detection to identify and block rhysida payloads.
  • Establish routine backups and isolate critical systems from direct internet access.
  • Educate users on recognizing malicious emails and avoiding suspicious links.

Suggested Tags

Ransomware
Cybercrime
Phishing
Financial-Gain
Cobalt Strike

Confidence Assessment

Confidence in Rhysida's threat profile is moderate due to limited detailed intelligence beyond their TTPs and known victims. Further data on their long-term strategies and additional campaign specifics would enhance understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 18 URL 2

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

6

Campaigns

127

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
Phishing
Cybercrime
Financial-Gain
Cobalt Strike

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jun 5, 2023
Last Seen
Jun 18, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.