Rhysida Ransomware

Malware updated 11 days ago (2024-09-29T18:01:14.136Z)
Download STIX
Preview STIX
The Rhysida ransomware group, a malicious software entity, has been actively launching cyberattacks since May 2023. Their modus operandi involves infiltrating systems through suspicious downloads, emails, or websites, often unbeknownst to the user. Once inside, they exploit and damage the system, stealing personal information, disrupting operations, or holding data hostage for ransom. The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) have issued warnings about the activities of this ransomware gang, highlighting the severity and widespread nature of their attacks. In August 2024, the Port of Seattle confirmed that it fell victim to an attack by the Rhysida ransomware group. This cyberattack affected critical systems, including those at the Seattle-Tacoma International Airport. In another significant incident, the group is believed to have knocked systems offline at Chicago's Lurie Children's Hospital, compromising records belonging to more than 790,000 patients. These attacks demonstrate the group's capacity to target and disrupt major infrastructure and healthcare services. The Rhysida ransomware group has also shown its willingness to leak stolen data if their ransom demands are not met. In July, after initially attacking the city of Columbus and demanding $1.9 million in Bitcoin, the group released 6.5 terabytes of data when the city refused to pay. Earlier in August, they leaked 3.1TB of data on their Tor-based site, claiming it was stolen from Columbus' systems. This data allegedly included sensitive information such as passports and Social Security numbers, underscoring the serious implications of these cyberattacks.
Description last updated: 2024-09-29T17:17:29.964Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Vice Society is a possible alias for Rhysida Ransomware. Vice Society, a threat actor or hacking team with malicious intent, has been active since 2022 and has made significant waves in the cybersecurity world. The group is known for deploying various forms of ransomware, including BlackCat, Quantum Locker, Zeppelin, and their own branded variant of Zeppe
6
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Ransomware
Ransom
Windows
Health
Malware
Vulnerability
Hospital
Healthcare
Medical
RaaS
Bitcoin
Encryption
Hospitals
Payload
Lateral Move...
Apt
Zero Day
CISA
Extortion
Cybercrime
Spyware
Exploit
Phishing
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The Lockbit Malware is associated with Rhysida Ransomware. LockBit is a notorious malware that has been involved in several high-profile ransomware incidents, including attacks on Boeing, London Drugs, Ontario hospitals, and Accenture. The malicious software infiltrates systems through suspicious downloads, emails, or websites, often unbeknownst to the userUnspecified
2
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
Alias DescriptionAssociation TypeVotes
The Rhysida Threat Actor is associated with Rhysida Ransomware. Rhysida, a threat actor group known for its malicious activities, has been actively executing ransomware attacks since May 2023. The group is known for its use of various families of ransomware to aid in double extortion attacks, including BlackCat, Hello Kitty, Quantum Locker, Rhysida, Zeppelin — iUnspecified
11
Source Document References
Information about the Rhysida Ransomware Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Securityaffairs
11 days ago
Securityaffairs
18 days ago
Checkpoint
24 days ago
Securityaffairs
25 days ago
DARKReading
a month ago
DARKReading
a month ago
Checkpoint
a month ago
Checkpoint
2 months ago
Securityaffairs
2 months ago
Securityaffairs
2 months ago
Securityaffairs
2 months ago
Checkpoint
2 months ago
Securityaffairs
2 months ago
Checkpoint
3 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
BankInfoSecurity
3 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
BankInfoSecurity
3 months ago