Rhysida (Windows)

First seen
2023-06-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:11:36

Targeted industries: healthcare-and-pharmaceutical education-and-nonprofits government-and-public-sector

Context

Rhysida is a ransomware family that primarily targets organizations across various sectors, including healthcare, education, and government. It encrypts files on Windows systems, demanding a ransom payment to restore access. The malware is part of a rising trend in cybercrime operations focused on exploiting vulnerabilities in critical sectors.

Reports & references

  • fourcore.io — Rhysida Ransomware History Ttp Adversary Emulation (report)
  • detect.fyi — Rhysida Ransomware And The Detection Opportunities 3599E9A02Bb2 (report)
  • research.checkpoint.com — The Rhysida Ransomware Activity Analysis And Ties To Vice Society (report)
  • shadowstackre.com — Rhysida (report)
  • go.recordedfuture.com — Cta 2025 0130 (report)
  • go.recordedfuture.com — Cta 2024 1009 (report)
  • threatdown.com — Rhysida Using Oyster Backdoor To Deliver Ransomware (report)
  • Cisco Talos — Emerging Interlock Ransomware (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Rhysida (report)
  • sentinelone.com — Rhysida Ransomware Raas Crawls Out Of Crimeware Undergrowth To Attack Chilean Army (report)
  • Cisco Talos — Rhysida Ransomware (report)
  • at-bay.com — Rhysida Evading Detection (report)
  • secplicity.org — Scratching The Surface Of Rhysida Ransomware (report)
  • bleepingcomputer.com — Rhysida Ransomware Behind Recent Attacks On Healthcare (report)
  • fortinet.com — Investigating The New Rhysida Ransomware (report)
  • helpnetsecurity.com — Rhysida Ransomware Decryptor (report)
  • Trend Micro — An Overview Of The New Rhysida Ransomware (report)
  • decoded.avast.io — Rhysida Ransomware Technical Analysis (report)
  • linkedin.com — Prodaft Organic Relationship Between Rhysida Vice Activity 7091777236663427072 Nqes (report)

External references