Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks and Cobalt Strike to breach the targets' networks and deploy their payloads.<br> <br> The group threatens to publicly distribute exfiltrated data if the ransom is not paid, and it's worth mentioning that Rhysida is still in the early stages of development.<br> <br> The ransomware leaves PDF notes in the affected folders, instructing victims to contact the group through its portal, and payment is made via Bitcoin.<br> <br> After encryption, the ransomware appends the extension '.ryshida' to encrypted files.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs Known victims: 269 1 ransom note(s) on file
Objectives
Executive Summary
Rhysida, a ransomware-as-a-service (RAAS) group emerged in May 2023, utilizing phishing and Cobalt Strike for network breaches. Their campaigns target various sectors globally, leaving '.ryshida' file extensions and demanding Bitcoin ransoms, with threats of data distribution as leverage.
Goals & Targeting
Rhysida's primary goal is financial gain. Their targeting strategy focuses on maximizing profit through widespread campaigns rather than sector-specific attacks. victims include educational institutions, healthcare providers, and corporate entities in various countries, with a preference for easy compromise targets.
Enhanced Description
Rhysida is a mid-tier ransomware operation that leverages phishing emails to distribute their malware, which requires Cobalt Strike for initial breach execution. Once deployed, the rhysida ransomware encrypts files and appends '.ryshida' extensions. Victims are instructed to contact via a portal for decryption keys. Ransoms are paid in Bitcoin, with the group threatening data leaks if payments aren't made. Since their emergence, they have targeted organizations across multiple sectors including education, healthcare, and local government.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Rhysida has carried out numerous campaigns across North America and Europe, targeting sectors like education and healthcare. Their recent operations include attacks against Stelia North America and Southold Town Senior Services, indicating a preference for critical infrastructure and organizations with less robust defenses.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Rhysida's threat profile is moderate due to limited detailed intelligence beyond their TTPs and known victims. Further data on their long-term strategies and additional campaign specifics would enhance understanding.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
6
Campaigns
127
IOCs
0
Observed Data
0
Tactics