mor3intel logo
mor3intelThreat Intelligence
DashboardVictimsGroupsCountriesStatsATT&CKRulesIOC Lookup
InstagramTelegram
5 Active Threats
Back to Dashboard

Rhysida

active

Also known as: Rhysida Ransomware

Rhysida is a ransomware group that emerged in May 2023 and has quickly become a significant threat, particularly to the healthcare and education sectors. They operate a leak site and use double extortion tactics.

First Seen

2023-05

Last Activity

2025-01

Target Regions

4 regions

Industries

5 sectors

HealthcareEducationGovernmentManufacturingIT
Attack Chain (MITRE ATT&CK)
Visual representation of the attack phases and techniques used by Rhysida

Click on a phase to view details and MITRE ATT&CK technique IDs

Tactics & Techniques
MITRE ATT&CK mapped tactics and techniques used by this threat actor
Technique IDNameTacticDescriptionReference
T1133External Remote ServicesInitial AccessExploits exposed VPN and RDP servicesMITRE
T1486Data Encrypted for ImpactImpactChaCha20 encryption with .rhysida extensionMITRE
Indicators of Compromise (IOCs)
Known IOCs associated with Rhysida operations
TypeValueDescriptionLast SeenActions
hasha7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8Rhysida ransomware loader2025-01-12
filenameCriticalBreachDetected.pdfRansom note PDF—

IOCs are defanged for safety. Click copy to get the clean value.

Detection Guidance
SIEM and EDR detection recommendations for identifying Rhysida activity
  • 1
    Monitor for unusual RDP connections
  • 2
    Detect PsExec execution across network
  • 3
    Alert on mass file encryption
  • 4
    Monitor for PDF ransom notes
Mitigation, Containment & Recovery
Step-by-step guidance for responding to and recovering from this ransomware attack
  • 1
    Disable exposed RDP
  • 2
    Implement VPN MFA
  • 3
    Block known Rhysida IOCs
mor3intel logomor3intel

This platform is intended for defensive cybersecurity, incident response, and recovery purposes only. Information provided is for educational and defensive use.

@mor3cod3@mor3cod3
© 2026 mor3intel