Rhysida Ransomware

Description Summary

Rhysida ransomware emerged in May 2023 as a ransomware-as-a-service. It is named after the Rhysida genus of centipedes, which is reflected in its leak-site branding. Rhysida is notable for high-profile attacks on healthcare and education, including the British Library and several U.S. school districts.

Threat Actor

The Rhysida group is assessed to overlap with the Vice Society actor. Initial access is most often via phishing campaigns, valid credentials, and VPN exploitation.

Technical Indicators

Encryption Extension
.rhysida
Encryption Algorithm
ChaCha20 + 4096-bit RSA-OAEP
Ransom Note Name
CriticalBreachDetected.pdf
Targeted Industries
Healthcare, Education, Manufacturing, Government
First Seen
May 2023
Last Seen
Active
Geographical Location
North America, Europe (notable U.K. impact)

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 3 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 3 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop
Initial Access Persistence x 1 T1078.002 Valid Accounts: Domain Accounts