Aller au contenu principal
Retour à la base de rançongiciels
Groupe de rançongiciel

rhysida

Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks and Cobalt Strike to breach the targets' networks and deploy their payloads.<br> <br> The group threatens to publicly distribute exfiltrated data if the ransom is not paid, and it's worth mentioning that Rhysida is still in the early stages of development.<br> <br> The ransomware leaves PDF notes in the affected folders, instructing victims to contact the group through its portal, and payment is made via Bitcoin.<br> <br> After encryption, the ransomware appends the extension '.ryshida' to encrypted files.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs

Victimes connues281

Niveau de menace

ÉLEVÉ

Tactiques, techniques et procédures (TTP)

DiscoveryEnum

  • PowerView

Exfiltration

  • WinSCP

LOLBAS

  • NTDS Utility (ntdsutil)
  • PsExec
  • WMIC
  • Windows Event Utility (wevtutil)

Offsec

  • Impacket

RMM-Tools

  • AnyDesk
0

Vérifier si vous êtes touché

Cherchez dans notre base si votre organisation figure sur la liste des victimes de rhysida.

Essayez maintenantGratuit⌘K
Exemple

score de risque · catégories de menace · sources · ancienneté · confiance — en une requête

Autres groupes de rançongiciel actifs