Ransomware Group: rhysida

Fecha
25 Jun 2026
Actor
rhysida
Tipo
Threat-actor
Pais
Unknown
Sector
-
Confianza
high
63
Prioridad analitica
Media

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

1IOCs
1TTPs
rhysidaActor
UnknownPais
Executive Summary
Perfil del grupo segun ransomware.anggipradana.com.

Key Points

  • Ransomware Dashboard

Grupo Ransomware: rhysida

Perfil del grupo segun ransomware.anggipradana.com.

CampoValor
Alias
Pais
Estado

Descripcion

Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks and Cobalt Strike to breach the targets' networks and deploy their payloads.<br> <br> The group threatens to publicly distribute exfiltrated data if the ransom is not paid, and it's worth mentioning that Rhysida is still in the early stages of development.<br> <br> The ransomware leaves PDF notes in the affected folders, instructing victims to contact the group through its portal, and payment is made via Bitcoin.<br> <br> After encryption, the ransomware appends the extension '.ryshida' to encrypted files.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs

Referencias

Diamond Model

Adversary
rhysida
Ver perfil →
Victim
Ransomware Group: rhysida
Capability
Threat-actor
1 TTPs MITRE
Infrastructure
github.com

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
Domain github.com Extraido del contenido VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor rhysida en el blog → Ver rhysida en IntelTracker → URL IntelTracker: ransomware.anggipradana.com → Fuente OSINT: ransomware.anggipradana.com → Buscar rhysida en APTTrail → Repositorio APTTrail → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes