Description
Rhysida is a ransomware operation that first emerged in May 2023, and it presents itself as a security service that highlights alleged vulnerabilities while demanding ransom payment. Its affiliates encrypt Windows and Linux systems, exfiltrate data, and publish stolen material on a leak site when negotiations fail. Campaigns have hit healthcare, education, and government organizations, and the group's theatrical branding reflects the attention economy of modern extortion.
Stats
- First seen
- May 2023
- Last seen
- October 2026
Alert name variants
| Alert Name |
|---|
| Gen:Variant.Ransom.Rhysida.10 |
| Gen:Variant.Ransom.Rhysida.14 |
| Gen:Variant.Ransom.Rhysida.5 |
| Gen:Variant.Ransom.Rhysida.6 |
| Gen:Variant.Ransom.Rhysida.9 |
| Linux.Ransomware.Rhysida |
| Shortcut.Ransomware.Rhysida |
| Shortcut.Trojan.Rhysida |
| Trojan.Ransom.Rhysida.B |
| Trojan.Ransom.Rhysida.C |
