Rhysida Ransomware
Was ist Rhysida Ransomware?
Rhysida RansomwareA ransomware-as-a-service group first observed in May 2023, known for targeting healthcare, education, and government victims and for high-profile attacks including the British Library and Insomniac Games breaches.
Rhysida is a ransomware-as-a-service group that emerged in May 2023 and quickly became one of the more active newcomers in the 2023–2025 cybercrime landscape, joining a wave of post-LockBit/post-ALPHV operators. The encryptor is written in C++ and uses AES-256 plus ChaCha20 hybrid encryption with file extensions changed to `.rhysida`, leaving the ransom note `CriticalBreachDetected.pdf`. Rhysida favors double-extortion: it exfiltrates data to its 'Rhysida' Tor leak site before encryption and lists victims publicly to pressure payment. The actor has hit a notably broad mix of sectors — local government, K-12 schools, hospitals (Prospect Medical, several U.K. NHS supply chains), the British Library (October 2023, a months-long outage), and Insomniac Games (Sony, December 2023). Initial access has included VPN credentials harvested by info-stealers, phishing, and exploitation of known vulnerabilities; affiliates often use Cobalt Strike, AnyDesk/Atera, and Mimikatz post-exploitation. CISA, the FBI, MS-ISAC, and U.K. NCSC published joint advisories on Rhysida TTPs in late 2023.
● Beispiele
- 01
Rhysida claimed responsibility for the October 2023 British Library attack, which disrupted catalog, payment, and IT systems for many months.
- 02
An MSSP detects Rhysida pre-encryption by alerting on Atera / AnyDesk installations on unmanaged servers, a recurring tradecraft pattern.
● Häufige Fragen
Was ist Rhysida Ransomware?
A ransomware-as-a-service group first observed in May 2023, known for targeting healthcare, education, and government victims and for high-profile attacks including the British Library and Insomniac Games breaches. Es gehört zur Kategorie Schadsoftware der Cybersicherheit.
Was bedeutet Rhysida Ransomware?
A ransomware-as-a-service group first observed in May 2023, known for targeting healthcare, education, and government victims and for high-profile attacks including the British Library and Insomniac Games breaches.
Wie funktioniert Rhysida Ransomware?
Rhysida is a ransomware-as-a-service group that emerged in May 2023 and quickly became one of the more active newcomers in the 2023–2025 cybercrime landscape, joining a wave of post-LockBit/post-ALPHV operators. The encryptor is written in C++ and uses AES-256 plus ChaCha20 hybrid encryption with file extensions changed to `.rhysida`, leaving the ransom note `CriticalBreachDetected.pdf`. Rhysida favors double-extortion: it exfiltrates data to its 'Rhysida' Tor leak site before encryption and lists victims publicly to pressure payment. The actor has hit a notably broad mix of sectors — local government, K-12 schools, hospitals (Prospect Medical, several U.K. NHS supply chains), the British Library (October 2023, a months-long outage), and Insomniac Games (Sony, December 2023). Initial access has included VPN credentials harvested by info-stealers, phishing, and exploitation of known vulnerabilities; affiliates often use Cobalt Strike, AnyDesk/Atera, and Mimikatz post-exploitation. CISA, the FBI, MS-ISAC, and U.K. NCSC published joint advisories on Rhysida TTPs in late 2023.
Wie schützt man sich gegen Rhysida Ransomware?
Schutzmaßnahmen gegen Rhysida Ransomware kombinieren typischerweise technische Kontrollen und operative Praktiken, wie in der Definition oben beschrieben.
Welche anderen Bezeichnungen gibt es für Rhysida Ransomware?
Übliche alternative Bezeichnungen: Rhysida.
● Verwandte Begriffe
- malware№ 1004
Ransomware
Schadsoftware, die Daten des Opfers verschlüsselt oder Systeme sperrt und für die Wiederherstellung des Zugriffs ein Lösegeld fordert.
- malware№ 1006
Ransomware-as-a-Service (RaaS)
Ein kriminelles Geschäftsmodell, bei dem Ransomware-Betreiber ihre Malware und Infrastruktur an Affiliates vermieten, die die Angriffe ausführen und die Beute teilen.
- defense-ops№ 1005
Ransomware-Bande
Finanziell motivierte Cybercrime-Gruppe, die Ransomware entwickelt, betreibt oder verteilt, um Organisationen ueber Verschluesselung und Datenleak-Drohungen zu erpressen.
- attacks№ 307
Datenleck
Versehentliche oder fahrlaessige Offenlegung sensibler Daten, meist durch Fehlkonfiguration oder menschliches Versagen statt durch einen aktiven Angreifer.
- defense-ops№ 695
LockBit
Russischsprachige Ransomware-as-a-Service-Operation, die zwischen 2022 und 2024 zum aktivsten Ransomware-Brand weltweit wurde, bevor Operation Cronos sie schwer traf.
- defense-ops№ 115
BlackCat / ALPHV
In Rust geschriebene Ransomware-as-a-Service-Operation Ende 2021 bis 2024, bekannt fuer plattformuebergreifende Encryptoren und aggressive mehrstufige Erpressung.