Rhysida (Windows)
- First seen
- 2023-06-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:11:36
Targeted industries: healthcare-and-pharmaceutical education-and-nonprofits government-and-public-sector
Context
Rhysida is a ransomware family that primarily targets organizations across various sectors, including healthcare, education, and government. It encrypts files on Windows systems, demanding a ransom payment to restore access. The malware is part of a rising trend in cybercrime operations focused on exploiting vulnerabilities in critical sectors.
Reports & references
- fourcore.io — Rhysida Ransomware History Ttp Adversary Emulation (report)
- detect.fyi — Rhysida Ransomware And The Detection Opportunities 3599E9A02Bb2 (report)
- research.checkpoint.com — The Rhysida Ransomware Activity Analysis And Ties To Vice Society (report)
- shadowstackre.com — Rhysida (report)
- go.recordedfuture.com — Cta 2025 0130 (report)
- go.recordedfuture.com — Cta 2024 1009 (report)
- threatdown.com — Rhysida Using Oyster Backdoor To Deliver Ransomware (report)
- Cisco Talos — Emerging Interlock Ransomware (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Rhysida (report)
- sentinelone.com — Rhysida Ransomware Raas Crawls Out Of Crimeware Undergrowth To Attack Chilean Army (report)
- Cisco Talos — Rhysida Ransomware (report)
- at-bay.com — Rhysida Evading Detection (report)
- secplicity.org — Scratching The Surface Of Rhysida Ransomware (report)
- bleepingcomputer.com — Rhysida Ransomware Behind Recent Attacks On Healthcare (report)
- fortinet.com — Investigating The New Rhysida Ransomware (report)
- helpnetsecurity.com — Rhysida Ransomware Decryptor (report)
- Trend Micro — An Overview Of The New Rhysida Ransomware (report)
- decoded.avast.io — Rhysida Ransomware Technical Analysis (report)
- linkedin.com — Prodaft Organic Relationship Between Rhysida Vice Activity 7091777236663427072 Nqes (report)