Skip to content
The Nexus
Group profile11 claimed in last 30d15 total tracked

rhysida

Forward this

Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks and Cobalt Strike to breach the targets' networks and deploy their payloads. The group threatens to publicly distribute exfiltrated data if the ransom is not paid, and it's worth mentioning that Rhysida is still in the early stages of development. The ransomware leaves PDF notes in the affected folders, instructing victims to contact the group through its portal, and payment is made via Bitcoin. After encryption, the ransomware appends the extension '.ryshida' to encrypted files. Source: https://github.com/crocodyli/ThreatActors-TTPs

First seen: May 19 · 10:24 UTCLast seen: Aug 22 · 05:55 UTCTracked since: 2023-06-05
Sectors hit
  • Healthcare2
  • Public Sector1
  • Unspecified1
  • Government & Defense1
  • Energy & Utilities1
  • Education1
  • Construction1
Countries hit
  • United States5
  • Germany1
  • Australia1
MITRE ATT&CK · observed TTPs12 tactics

Tactics and techniques attributed to RHYSIDA by ransomware.live's curated TTP catalog. Identifiers link to the canonical MITRE ATT&CK reference for each tactic or sub-technique.

  • TA0001Initial Access
    • T1548.002Abusing Elevation Control Mechanism: Bypass User Account Control

      Bypassing UAC for access.

    • T1566Phishing

      Phishing for initial access.

  • TA0002Execution
    • T1059Command and Scripting Interpreter

      Using command interpreters for execution.

    • T1129Shared Modules

      Using shared modules.

  • TA0003Persistence
    • T1547.001Registry Run Keys / Startup Folder

      Persistence via registry run keys.

  • TA0004Privilege Escalation
    • T1055Process Injection

      Injecting into processes for privilege escalation.

    • T1055.003Thread Execution Hijacking

      Hijacking thread execution.

    • T1547.001Registry Run Keys

      Using registry run keys.

  • TA0005Defense Evasion
    • T1027Obfuscated Files or Information

      Obfuscating files and information.

    • T1036Masquerading

      Masquerading malicious files.

    • T1055Process Injection

      Process injection for evasion.

    • T1055.003Thread Execution Hijacking

      Thread execution hijacking.

    • T1497Virtualization/Sandbox Evasion

      Evading virtualization/sandbox detection.

    • T1564Hidden Artifacts

      Hiding artifacts.

    • T1564.004NTFS File Attributes

      Using NTFS file attributes.

    • T1620Reflective DLL Injection

      Reflective DLL injection.

  • TA0007Discovery
    • T1010Application Window Discovery

      Discovering application windows.

    • T1057Process Discovery

      Discovering running processes.

    • T1082System Information Discovery

      Discovering system information.

    • T1083File and Directory Discovery

      Discovering files and directories.

    • T1497Virtualization/Sandbox Evasion

      Detecting virtualization/sandbox.

    • T1518.001Security Software Discovery

      Discovering security software.

  • TA0009Collection
    • T1005Data from Local System

      Collecting data from local system.

    • T1119Automated Collection

      Automated data collection.

  • TA0010Exfiltration
    • T1041Exfiltration Over C2 Channel

      Exfiltrating data over C2 channel.

  • TA0011Command and Control
    • T1071Application Layer Protocol

      Using application layer protocols.

    • T1071.001Web Protocols

      Using web protocols for C2.

  • TA0040Impact
    • T1486Data Encrypted for Impact

      Encrypting data for impact.

  • TA0042Resource Development
    • T1583Acquire Infrastructure

      Acquiring infrastructure for operations.

    • T1587Develop Capabilities

      Developing malware capabilities.

  • TA0043Reconnaissance
    • T1595Active Scanning

      Scanning for vulnerable targets.

    • T1598Phishing for Information

      Gathering information through phishing.

Recent claimed victims
Energy & UtilitiesUnited StatesAug 22 · 05:56 UTC

CRI Electric

crielectric.com
Aug 21 · 16:27 UTC

Fairview Dental Group

HealthcareUnited StatesAug 21 · 12:28 UTC

Fairview Dental Group

Aug 21 · 12:23 UTC

Battle Creek Public Schools

EducationUnited StatesAug 21 · 10:28 UTC

Battle Creek Public Schools

battlecreekschools.net
Government & DefenseUnited StatesAug 14 · 10:00 UTC

Pierce Township

piercetownship.org
HealthcareAustraliaAug 13 · 17:57 UTC

SIA Medical Centre

siamed.com.au
ConstructionJun 18 · 14:29 UTC

Lawson Roofing

United StatesMay 25 · 17:25 UTC

IDS Group

idsgi.com
Public SectorGermanyMay 19 · 10:24 UTC

Landeshauptstadt Stuttgart

stuttgart.de