Ransomware Group intelligence
Rhysida
ActiveTrack Rhysida with 311 published victims and 7 known leak locations in a single intelligence view.
Overview
Rhysida is tracked by Dark Eye as a ransomware group with 311 published victims.
United States is currently the most targeted country in this dataset.
7 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 15 38.5%
- Pending 24 61.5%
- Deleted 0 0.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (7)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 7 | Onion service | Up checked 4h ago | rhysidaqho36b6i6mvpmy5di4ro5zglovtxixrirky6q3fgack7q5uyd.onion |
| Leak location 4 | Onion service | Up checked 4h ago | rhysidafc6lm7qa2mkiukbezh7zuth3i4wof4mh2audkymscjm6yegad.onion |
| Leak location 1 | Onion service | Up checked 4h ago | rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion |
| Leak location 2 | Onion service | Up checked 4h ago | rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion |
| Leak location 3 | Onion service | Up checked 4h ago | rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion |
| Leak location 6 | Onion service | Down checked 4h ago | rhysidaeoxtkejwuheks3a7htk4zn3dfuynt5mqw6oawlcx6kcxjdeyd.onion |
| Leak location 5 | Onion service | Down checked 4h ago | grhysidafc6lm7qa2mkiukbezh7zuth3i4wof4mh2audkymscjm6yegad.onion |
Top Activity Sectors (17)
- Not identified 47
- Education 44
- Communication / Marketing 41
- Healthcare / Pharma 33
- Public Sector 27
- Manufacturing / Engineering 18
- Finance / Legal / Insurance 16
- Services 14
- Retail / E-commerce 7
- IT 7
- NGOs / Associations 6
- Transportation / Travel / Logistics 6
- Construction / Real Estate 5
- Telecommunications 3
- Hospitality / Food & Beverage / Tourism 3
- Energy 2
- Agriculture / Food 1
Typical Attacks (9)
▼MITRE ATT&CK does not currently catalogue Rhysida, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: rhysida executes malicious commands via PowerShell scripts to stage payloads and manipulate system behavior.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: rhysida modifies registry run keys to ensure malware execution upon system reboot for persistence.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: rhysida disables antivirus tools and security software to prevent detection and hinder incident response efforts.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.016 Junk Code Insertion Stealth
What they do: rhysida inserts junk code into legitimate binaries to evade static analysis and detection by security tools.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: rhysida deletes Volume Shadow Copies and backup directories via vssadmin and native commands to eliminate recovery options.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: rhysida performs remote system discovery to identify additional hosts for lateral movement within the victim network.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: rhysida scans network shares using Windows tools to identify victim files and expand foothold across the network.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: rhysida exfiltrates stolen data via encrypted channels to pressure victims into paying ransom.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: rhysida encrypts victim files using custom ransomware binaries targeting critical data across affected systems.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Tools Observed (8)
▼Software Rhysida has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Dark Eye.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
CriticalBreachDetected.txt
Critical Breach Detected - Immediate Response Required Dear company, This is an automated alert from cybersecurity team Rhysida. An unfortunate situation has arisen - your digital ecosystem has been compromised, and a substantial amount of confidential data has been exfiltrated from your network. The potential ramifications of this could be dire, including the sale, publication, or distribution of your data to competitors or media outlets. This could inflict significant reputational and financial damage. However, this situation is not without a remedy. Our team has developed a unique key, specifically designed to restore your digital security. This key represents the first and most crucial step in recovering from this situation. To utilize this key, visit our secure portal: rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion with your secret key [snip] It's vital to note that any attempts to decrypt the encrypted files independently could lead to permanent data loss. We strongly advise against such actions. Time is a critical factor in mitigating the impact of this breach. With each passing moment, the potential damage escalates. Your immediate action and full cooperation are required to navigate this scenario effectively. Rest assured, our team is committed to guiding you through this process. The journey to resolution begins with the use of the unique key. Together, we can restore the security of your digital environment. Best regards
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (311)
Search, filter and paginate the victim timeline for Rhysida. Showing 301–311 of 311.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | EDER id6926 View details | Austria | Manufacturing / Engineering | pending | ||
|
EDER The EDER group of companies includes the brick plants in Peuerbach and Weibern, four ready-mixed concrete plants in Upper Austria, Systembau Eder with prefabricated stairs, constructive concrete components and double-wall systems for industrial building construction and its own vehicle fleet. Documents 100% All files was uploaded to public access, data hunters, enjoy More |
||||||
| Ransomware | Tyconz id6924 View details | Public Sector | — | |||
|
Tyconz Founded in 2011, TYCONZ has become one of the most experienced SAP-certified consultancy firms. Documents 100% All files was uploaded to public access, data hunters, enjoy More |
||||||
| Ransomware | Ziegelwerk Eder id6922 View details | Austria | Public Sector | — | ||
|
Ziegelwerk Eder In 1996, the Upper Austrian family company EDER built a state-of-the-art brick factory in Freital near Dresden. Documents 100% All files was uploaded to public access, data hunters, enjoy More |
||||||
| Ransomware | Koper Automatisering id6881 View details | Netherlands | Construction / Real Estate | — | ||
|
Koper Automatisering Koper Automatisering specializes in the development of specialized software for the food industry and floriculture. Documents 100% All files was uploaded to public access, data hunters, enjoy More |
||||||
| Ransomware | Paris High School id6824 View details | Education | — | — | ||
|
Paris High School Paris High School is a learning community dedicated to developing well-rounded, productive, engaged citizens in a safe and supportive environment. More |
||||||
| Ransomware | Northeastern State University id6823 View details | United States | Education | — | — | |
|
Northeastern State University Northeastern State University is a public university with its main campus in Tahlequah, Oklahoma. More |
||||||
| Ransomware | Ejercito de Chile id6803 View details | Chile | Public Sector | — | — | |
|
Ejercito de Chile The Army of Chile is the branch of the Armed Forces of Chile in charge of the land defense of Chile, whose mission is to maintain the external security, sovereignty and territorial integrity of the Republic. More |
||||||
| Ransomware | Haemokinesis id6736 View details | Retail / E-commerce | — | |||
|
Haemokinesis Haemokinesis specializes in research and development, laboratory systems, sales and distribution of immunohematology products. Documents 100% all files was uploaded to public access, data hunters, enjoy More |
||||||
| Ransomware | Amstutz Produkte id6735 View details | Switzerland | Communication / Marketing | — | ||
|
Amstutz Produkte AMSTUTZ PRODUKTE AG is a leading Swiss manufacturer of chemicals and technical equipment for chemical applications. Documents 100% all files was uploaded to public access, data hunters, enjoy More |
||||||
| Ransomware | The Thomas Hardye School id6734 View details | Education | — | |||
|
The Thomas Hardye School The Thomas Hardye School is a secondary academy school in Dorchester, Dorset, England. It is also part of the DASP group. Documents 100% all files was uploaded to public access, data hunters, enjoy More |
||||||
| Ransomware | Collectivite Territoriale de Martinique id6733 View details | Martinique | Public Sector | — | ||
|
Collectivite Territoriale de Martinique The territorial collectivity of Martinique is a single French territorial collectivity that succeeds the overseas department and region of Martinique in all their rights and obligations on January 1, 2016. Documents 100% all files was uploaded to public access, data hunters, enjoy More |
||||||