Rhysida

Active
Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks and Cobalt Strike to breach the targets' networks and deploy their payloads.

The group threatens to publicly distribute exfiltrated data if the ransom is not paid, and it's worth mentioning that Rhysida is still in the early stages of development.

The ransomware leaves PDF notes in the affected folders, instructing victims to contact the group through its portal, and payment is made via Bitcoin.

After encryption, the ransomware appends the extension '.ryshida' to encrypted files.
Source: https://github.com/crocodyli/ThreatActors-TTPs
286 Victims
Jun 5, 2023 First Discovered
Sep 12, 2026 Last Discovered
5 Days Inactive
0% Infostealer
2/2 Sites Online
Known Locations (2)
rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion
Rhysida
rhysidafc6lm7qa2mkiukbezh7zuth3i4wof4mh2audkymscjm6yegad.onion
Tools Used
DiscoveryEnum
PowerView
Exfiltration
WinSCP
LOLBAS
NTDS Utility (ntdsutil), PsExec, WMIC, Windows Event Utility (wevtutil)
Offsec
Impacket
RMM-Tools
AnyDesk
Intelligence
Victims (286)

Detailed victim list temporarily unavailable

This group has 286 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.