Description Summary
Rhysida ransomware emerged in May 2023 as a ransomware-as-a-service. It is named after the Rhysida genus of centipedes, which is reflected in its leak-site branding. Rhysida is notable for high-profile attacks on healthcare and education, including the British Library and several U.S. school districts.
Threat Actor
The Rhysida group is assessed to overlap with the Vice Society actor. Initial access is most often via phishing campaigns, valid credentials, and VPN exploitation.
Technical Indicators
Encryption Extension
.rhysida
Encryption Algorithm
ChaCha20 + 4096-bit RSA-OAEP
Ransom Note Name
CriticalBreachDetected.pdf
Targeted Industries
Healthcare, Education, Manufacturing, Government
First Seen
May 2023
Last Seen
Active
Geographical Location
North America, Europe (notable U.K. impact)
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 3 | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| T1078 | Valid Accounts | |
| Execution x 1 | T1059 | Command and Scripting Interpreter |
| Execution Persistence x 1 | T1053 | Scheduled Task/Job |
| Defense Evasion x 2 | T1562.001 | Disable or Modify Tools |
| T1070.004 | File Deletion | |
| Discovery x 2 | T1083 | File and Directory Discovery |
| T1082 | System Information Discovery | |
| Lateral Movement x 2 | T1021.001 | Remote Services: RDP |
| T1021.002 | SMB/Windows Admin Shares | |
| Exfiltration x 2 | T1041 | Exfiltration Over C2 Channel |
| T1567.002 | Exfiltration to Cloud Storage | |
| Impact x 3 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop | |
| Initial Access Persistence x 1 | T1078.002 | Valid Accounts: Domain Accounts |