rhysida
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 08:53
- Modified
- 21/12/2025 18:19
- Updated at
- 21/12/2025 18:19
- Revoked
- No
- Author / Source
- Ransomware.Live
- Resource level
- —
- Primary motivation
- —
- Related entities
- 2 reports, 32 attack patterns (mitre), 6 malware, 2 sectors, 2 countries, 155 indicators, 3 organization
Description
Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks and Cobalt Strike to breach the targets' networks and deploy their payloads.<br> <br> The group threatens to publicly distribute exfiltrated data if the ransom is not paid, and it's worth mentioning that Rhysida is still in the early stages of development.<br> <br> The ransomware leaves PDF notes in the affected folders, instructing victims to contact the group through its portal, and payment is made via Bitcoin.<br> <br> After encryption, the ransomware appends the extension '.ryshida' to encrypted files.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs
Marking (TLP)
TLP:CLEAR
Labels
ransomware