RH

Rhysida Ransomware

Active

Threat actor group tracked in the global ransomware database · Last disclosure: Sep 1, 2026

Ransomware-as-a-Service (RaaS) Double Extortion Target: Healthcare
203
Total Victims
0.9% of all tracked
23
Countries Targeted
17
Sectors Targeted
2024
First Seen

ThreatAI Analysis

Compiled from the ransomware.live profile for Rhysida and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Ransomware-as-a-service group Rhysida emerged in May 2023 and has already infected over two hundred victims across twenty-two countries - the us, Canada, and the uk being hit hardest.

Who Rhysida is

Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks and Cobalt Strike to breach the targets' networks and deploy their payloads. The group threatens to publicly distribute exfiltrated data if the ransom is not paid, and it's worth mentioning that Rhysida is still in the early stages of development. The ransomware leaves PDF notes in the affected folders, instructing victims to contact the group through its portal, and payment is made via Bitcoin. After encryption, the ransomware appends the extension '.ryshida' to encrypted files. Source: https://github.com/crocodyli/ThreatActors-TTPs

Recorded activity

Disclosures attributed to Rhysida in this database run from January 2024 to September 2026, totalling 203 victims — 0.9% of everything tracked here. Rhysida has listed victims in 23 countries in this database, most often United States, followed by Canada and United Kingdom. The sectors appearing most in its listings are Healthcare, Education, Business Services.

How Rhysida is documented to operate

Phishing T1566 Initial Access

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns. Adversaries may send victims emails containing malicious attachments or links, typically to execute malicious code on victim systems. Phishing may also be conducted via third-party services, like social media platforms.

Mitigations: Network Intrusion Prevention, Restrict Web-Based Content, User Training, Antivirus/Antimalware, Software Configuration, Audit

MITRE ATT&CK reference →
Command and Scripting Interpreter T1059 Execution

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell. There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic.

Mitigations: Restrict Web-Based Content, Limit Software Installation, Execution Prevention, Code Signing, Behavior Prevention on Endpoint, Privileged Account Management

MITRE ATT&CK reference →
Shared Modules T1129 Execution

Adversaries may execute malicious payloads via loading shared modules. Shared modules are executable files that are loaded into processes to provide access to reusable code, such as specific custom functions or invoking OS API functions (i.e., Native API). Adversaries may use this functionality as a way to execute arbitrary payloads on a victim system. For example, adversaries can modularize functionality of their malware into shared objects that perform various functions such as managing C2 network communications or execution of specific actions on objective. The Linux & macOS module loader can load and execute shared objects from arbitrary local paths.

Mitigations: Execution Prevention

MITRE ATT&CK reference →
Registry Run Keys / Startup Folder T1547.001 Persistence Privilege Escalation

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

MITRE ATT&CK reference →
Process Injection T1055 Stealth Privilege Escalation

Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process. There are many different ways to inject code into a process, many of which abuse legitimate functionalities.

Mitigations: Behavior Prevention on Endpoint, Privileged Account Management

MITRE ATT&CK reference →
Thread Execution Hijacking T1055.003 Stealth Privilege Escalation

Adversaries may inject malicious code into hijacked processes in order to evade process-based defenses as well as possibly elevate privileges. Thread Execution Hijacking is a method of executing arbitrary code in the address space of a separate live process. Thread Execution Hijacking is commonly performed by suspending an existing process then unmapping/hollowing its memory, which can then be replaced with malicious code or the path to a DLL. A handle to an existing victim process is first created with native Windows API calls such as <codeOpenThread</code.

Mitigations: Behavior Prevention on Endpoint

MITRE ATT&CK reference →
Obfuscated Files or Information T1027 Stealth

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses. Payloads may be compressed, archived, or encrypted in order to avoid detection. These payloads may be used during Initial Access or later to mitigate detection. Sometimes a user's action may be required to open and Deobfuscate/Decode Files or Information for User Execution. The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.

Mitigations: User Training, Behavior Prevention on Endpoint, Antivirus/Antimalware, Audit

MITRE ATT&CK reference →
Masquerading T1036 Stealth

Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names. Renaming abusable system utilities to evade security monitoring is also a form of Masquerading.

Mitigations: User Training, Execution Prevention, Code Signing, Behavior Prevention on Endpoint, User Account Management, Restrict File and Directory Permissions

MITRE ATT&CK reference →

MITRE ATT&CK techniques attributed to Rhysida across its recorded activity. They describe the group overall, not any single incident.

Tooling observed in Rhysida operations

  • PowerView
  • WinSCP
  • PsExec
  • WMIC
  • Impacket
  • AnyDesk

Software reported in use by Rhysida. Most are legitimate administration or transfer utilities; their presence in an environment is a signal to investigate, not proof of compromise.

Indicators of compromise

  • f6e5f0ed974c89e2b4a47989fc987c79
  • 6742fdde9d5fde37ac5a9c9cbb1f691f
  • 7cfba113342f78b5909f606c26fc1dc4
  • 6dd8c26f64df37d0c7645b63c9bba51f
  • 0cf5491278c7d87e8c3fc88c7f9f26ff
  • d86383882515b7a9218d5f69924feadf

Showing a sample of 28 MD5 on file. Hashes and network indicators published for Rhysida. Leak-site addresses are deliberately excluded. Indicators age quickly — treat a match as a starting point for investigation, and an absence of matches as no assurance.

Threat Actor Analysis

Rhysida is a ransomware threat group that has disclosed 203 victims in publicly accessible leak site data, representing 0.9% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Rhysida in our dataset dates to January 2024.

Geographically, Rhysida has targeted organisations in 23 countries. The most frequently targeted nation is United States with 122 victim organisations. Other heavily targeted nations include Canada, United Kingdom, Germany.

Industry-wise, Rhysida shows a concentration in the Healthcare, Education, Business Services sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime — conditions that increase ransom payment likelihood.

Like most modern ransomware operations, Rhysida likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.

Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 100 most recent of the 203 disclosures we hold for this group; use the link beneath it to page through all of them.

Recent Victim Disclosures (showing 100 of 203)

# Organization Country Sector Date
1 Szechenyi Programiroda Nonprofit Kf 🇭🇺 Hungary Other Sep 1, 2026
2 Berlin, Germany 🇩🇪 Germany Aug 28, 2026
3 Valley Health Team Healthcare Aug 28, 2026
4 CRI Electric crielectric.com 🇺🇸 United States Energy & Utilities Aug 22, 2026
5 Battle Creek Public Schools battlecreekschools.net 🇺🇸 United States Education Aug 21, 2026
6 Fairview Dental Group 🇺🇸 United States Healthcare Aug 21, 2026
7 Pierce Township piercetownship.org 🇺🇸 United States Government & Defense Aug 14, 2026
8 SIA Medical Centre siamed.com.au 🇱🇻 Latvia Healthcare Aug 13, 2026
9 Lawson Roofing Construction Jun 18, 2026
10 IDS Group idsgi.com 🇺🇸 United States May 25, 2026
11 Landeshauptstadt Stuttgart stuttgart.de 🇩🇪 Germany Public Sector May 19, 2026
12 Tower View Primary School towerview.staffs.sch.uk 🇬🇧 United Kingdom Education May 15, 2026
13 Stelia North America 🇺🇸 United States Manufacturing Apr 27, 2026
14 Southold Town Senior ServicesSouthold Police Department Public Sector Mar 2, 2026
15 Rohner rohnerspraybooths.com 🇨🇭 Switzerland Manufacturing Feb 23, 2026
16 Cheyenne & Arapaho Tribes cheyenneandarapaho-nsn.gov 🇺🇸 United States Public Sector Feb 17, 2026
17 Phoenix Art Museum phxart.org 🇺🇸 United States Education Feb 12, 2026
18 Leading Edge Speciali Business Services Feb 6, 2026
19 Lakeside Union School District lsusd.net 🇺🇸 United States Education Feb 4, 2026
20 Elabs elabs.de 🇸🇪 Sweden Technology Feb 2, 2026
21 MACT Health Board macthealth.org 🇺🇸 United States Healthcare Jan 29, 2026
22 Cytek Biosciences cytekbio.com 🇺🇸 United States Healthcare Jan 25, 2026
23 Jet-care International jet-care.com 🇨🇭 Switzerland Transportation/Logistics Jan 21, 2026
24 Charles Leonard Steel Services charlesleonardsteelservices.com 🇺🇸 United States Manufacturing Jan 6, 2026
25 Falk, Waas, Hernandez, Cortina, Solomon & Bonner Overview Metrics falkwaas.com 🇺🇸 United States Business Services Dec 30, 2025
26 Larry Pitt & Associates larrypitt.com 🇺🇸 United States Business Services Dec 19, 2025
27 YOKOSUKA GAKUIN yokosuka-gakuin.ac.jp 🇯🇵 Japan Education Dec 15, 2025
28 ***** *********** Dec 13, 2025
29 United Keetoowah Band of Cherokee Indians in Oklahoma ukbb-nsn.gov 🇺🇸 United States Public Sector Dec 12, 2025
30 Harbour Town Doctors harbourtowndoctors.com.au 🇦🇺 Australia Healthcare Dec 11, 2025
31 Woodard, Emhardt, Henry, Reeves & Wagner, LLP uspatent.com 🇺🇸 United States Business Services Dec 11, 2025
32 Kane's Furniture kanes.com 🇺🇸 United States Consumer Services Dec 7, 2025
33 SODISE sodise.com 🇫🇷 France Business Services Dec 6, 2025
34 Bo Beuckman Ford bobeuckmanford.com 🇺🇸 United States Consumer Services Dec 3, 2025
35 Cleveland County Sheriff's Office cso-ok.us 🇺🇸 United States Public Sector Dec 2, 2025
36 AGS Nov 26, 2025
37 Marlex Human Capital marlexhc.pl 🇵🇱 Poland Business Services Nov 25, 2025
38 Collge Superieur De Montreal csmontreal.ca 🇨🇦 Canada Education Nov 24, 2025
39 St. Joseph's Healthcare Hamilton stjoes.ca 🇨🇦 Canada Healthcare Nov 22, 2025
40 Wachusett School District MA wrsd.net 🇺🇸 United States Education Nov 21, 2025
41 Smoll & Banning, CPAs smollandbanning.com 🇺🇸 United States Financial Services Nov 18, 2025
42 Heart South Cardiovascular Group heartsouthpc.com 🇺🇸 United States Healthcare Nov 10, 2025
43 LMHT Associates lmht.com 🇺🇸 United States Nov 10, 2025
44 KISS FM kissfm.es 🇪🇸 Spain Telecommunication Nov 5, 2025
45 Automated Logistics Systems automatedlogistics.com 🇺🇸 United States Transportation/Logistics Nov 4, 2025
46 Invacare invacare.com 🇺🇸 United States Healthcare Nov 4, 2025
47 Spindletop Center spindletop.org 🇺🇸 United States Healthcare Oct 30, 2025
48 Bellflower Unified School District bellsd.org 🇺🇸 United States Education Oct 28, 2025
49 Gemini Group geminigroup.net 🇺🇸 United States Oct 28, 2025
50 Abilene Family Medical Associates abilenedocs.com 🇺🇸 United States Healthcare Oct 27, 2025
51 Peraso perasotech.com 🇨🇦 Canada Technology Oct 21, 2025
52 GEIGER geiger-antriebstechnik.de 🇩🇪 Germany Business Services Oct 17, 2025
53 Hematology Oncology Consultants hocpc.com 🇺🇸 United States Healthcare Oct 17, 2025
54 Sibbalds sibbalds.co.uk 🇬🇧 United Kingdom Business Services Oct 16, 2025
55 Tex-Tube tex-tube.com 🇺🇸 United States Manufacturing Oct 15, 2025
56 Furuno Electric furuno.com 🇯🇵 Japan Technology Oct 13, 2025
57 Sdii Global sdii-global.com 🇺🇸 United States Business Services Oct 9, 2025
58 JASCO Applied Sciences jasco.com 🇨🇦 Canada Technology Oct 7, 2025
59 Medstar Health medstarhealth.org 🇺🇸 United States Healthcare Oct 4, 2025
60 Peavey Electronics Corporation peavey.com 🇺🇸 United States Manufacturing Sep 29, 2025
61 The Maryland Department of Transportation 🇺🇸 United States Public Sector Sep 24, 2025
62 Coastal Pacific Xpress coastalpacificxpress.com 🇨🇦 Canada Transportation/Logistics Sep 10, 2025
63 Elite Trailers elitetrailers.com 🇺🇸 United States Manufacturing Sep 5, 2025
64 Firelands Scientific firelandsscientific.com 🇺🇸 United States Aug 28, 2025
65 ZCORP zcorp.com 🇺🇸 United States Technology Aug 27, 2025
66 Elkhart Independent School District elkhartisd.net 🇺🇸 United States Education Aug 20, 2025
67 Trans-Tex trans-tex.pl 🇵🇱 Poland Manufacturing Aug 12, 2025
68 Alascom Alascom.it 🇮🇹 Italy Technology Aug 10, 2025
69 Cookeville Regional Medical Center crmchealth.org 🇺🇸 United States Healthcare Aug 2, 2025
70 First Baptist Church of Hammond fbchammond.org 🇺🇸 United States Jul 29, 2025
71 Cardinal Services cardinalservices.org 🇺🇸 United States Business Services Jul 15, 2025
72 Florida Hand Center flhandcenter.com 🇺🇸 United States Healthcare Jul 8, 2025
73 Welthungerhilfe welthungerhilfe.de 🇩🇪 Germany Public Sector Jun 29, 2025
74 Coreix coreix.net 🇬🇧 United Kingdom Technology Jun 18, 2025
75 CNPC USA cnpc.com.cn 🇺🇸 United States Energy Jun 16, 2025
76 Hudson River Housing hudsonriverhousing.org 🇺🇸 United States Public Sector Jun 7, 2025
77 Cator Ruma & Associates catorruma.com 🇺🇸 United States Construction May 28, 2025
78 Carrera Chevrolet carrera.com.br 🇧🇷 Brazil Manufacturing May 26, 2025
79 Florida Lung floridalung.com 🇺🇸 United States Healthcare May 20, 2025
80 Termolar termolar.com.br 🇧🇷 Brazil Manufacturing May 18, 2025
81 Sao Camilo Cachoeiro de Itapemirim saocamilo.br 🇧🇷 Brazil Education May 14, 2025
82 Mountain View Mushrooms mountainviewmushrooms.com 🇺🇸 United States Agriculture and Food Production May 9, 2025
83 Mediprobe Research mediprobe.com 🇨🇦 Canada Healthcare May 5, 2025
84 Kalin Hobeltechnik kaelin-hobeltechnik.ch 🇨🇭 Switzerland Manufacturing May 3, 2025
85 Government of Peru Gob.pe 🇵🇪 Peru Public Sector May 1, 2025
86 Coop UQAM coopuqam.com 🇨🇦 Canada Education Apr 29, 2025
87 LaBella Associates labellapc.com 🇺🇸 United States Business Services Apr 28, 2025
88 MDB 🇺🇸 United States Technology Apr 26, 2025
89 Milicic milicic.com.ar 🇦🇷 Argentina Construction Apr 23, 2025
90 Acos Favorit acosfavorit.com.br 🇳🇴 Norway Manufacturing Apr 22, 2025
91 Oregon Department of Environmental Quality oregon.gov 🇺🇸 United States Public Sector Apr 15, 2025
92 Dimension Composite dimensioncomposite.com 🇨🇦 Canada Manufacturing Apr 12, 2025
93 Swiss Capitals Group swisscapitals.com 🇨🇭 Switzerland Financial Services Apr 6, 2025
94 Clarity Ventures clarity-ventures.com 🇺🇸 United States Technology Apr 2, 2025
95 Forrest City School District mustang.grsc.k12.ar.us 🇺🇸 United States Education Mar 28, 2025
96 Senior Support Services cphcare.ca 🇨🇦 Canada Healthcare Mar 27, 2025
97 Okeene Elementary School okeene.k12.ok.us 🇺🇸 United States Education Mar 25, 2025
98 Ted Hosmer Enterprises tedhosmer.com 🇺🇸 United States Consumer Services Mar 18, 2025
99 Cothron's Security Professionals cothrons.com 🇺🇸 United States Business Services Mar 14, 2025
100 British virgin islands London Office bvi.org.uk 🇬🇧 United Kingdom Public Sector Mar 9, 2025

Frequently Asked Questions

What is Rhysida ransomware?

Rhysida is a ransomware threat group that has claimed 203 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Rhysida attacked?

Rhysida has claimed 203 victims in our database, representing 0.9% of all tracked ransomware attacks. The most targeted countries are United States, Canada, United Kingdom, Germany.

Which countries does Rhysida target?

Rhysida has attacked organizations in 23 countries. The top targeted countries are: United States, Canada, United Kingdom, Germany.

Which industries does Rhysida target?

Rhysida most frequently targets the Healthcare, Education, Business Services sectors based on victim disclosures in our database.

Is Rhysida still active?

Rhysida's most recent victim disclosure in our database was on September 1, 2026. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.