Rhysida Ransomware
ActiveThreat actor group tracked in the global ransomware database · Last disclosure: Sep 1, 2026
ThreatAI Analysis
Compiled from the ransomware.live profile for Rhysida and from this database. Figures and technique mappings are quoted from the source data, not inferred.
Ransomware-as-a-service group Rhysida emerged in May 2023 and has already infected over two hundred victims across twenty-two countries - the us, Canada, and the uk being hit hardest.
Who Rhysida is
Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks and Cobalt Strike to breach the targets' networks and deploy their payloads. The group threatens to publicly distribute exfiltrated data if the ransom is not paid, and it's worth mentioning that Rhysida is still in the early stages of development. The ransomware leaves PDF notes in the affected folders, instructing victims to contact the group through its portal, and payment is made via Bitcoin. After encryption, the ransomware appends the extension '.ryshida' to encrypted files. Source: https://github.com/crocodyli/ThreatActors-TTPs
Recorded activity
Disclosures attributed to Rhysida in this database run from January 2024 to September 2026, totalling 203 victims — 0.9% of everything tracked here. Rhysida has listed victims in 23 countries in this database, most often United States, followed by Canada and United Kingdom. The sectors appearing most in its listings are Healthcare, Education, Business Services.
How Rhysida is documented to operate
Phishing T1566 Initial Access
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns. Adversaries may send victims emails containing malicious attachments or links, typically to execute malicious code on victim systems. Phishing may also be conducted via third-party services, like social media platforms.
Mitigations: Network Intrusion Prevention, Restrict Web-Based Content, User Training, Antivirus/Antimalware, Software Configuration, Audit
MITRE ATT&CK reference →Command and Scripting Interpreter T1059 Execution
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell. There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic.
Mitigations: Restrict Web-Based Content, Limit Software Installation, Execution Prevention, Code Signing, Behavior Prevention on Endpoint, Privileged Account Management
MITRE ATT&CK reference →Shared Modules T1129 Execution
Adversaries may execute malicious payloads via loading shared modules. Shared modules are executable files that are loaded into processes to provide access to reusable code, such as specific custom functions or invoking OS API functions (i.e., Native API). Adversaries may use this functionality as a way to execute arbitrary payloads on a victim system. For example, adversaries can modularize functionality of their malware into shared objects that perform various functions such as managing C2 network communications or execution of specific actions on objective. The Linux & macOS module loader can load and execute shared objects from arbitrary local paths.
Mitigations: Execution Prevention
MITRE ATT&CK reference →Registry Run Keys / Startup Folder T1547.001 Persistence Privilege Escalation
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
MITRE ATT&CK reference →Process Injection T1055 Stealth Privilege Escalation
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process. There are many different ways to inject code into a process, many of which abuse legitimate functionalities.
Mitigations: Behavior Prevention on Endpoint, Privileged Account Management
MITRE ATT&CK reference →Thread Execution Hijacking T1055.003 Stealth Privilege Escalation
Adversaries may inject malicious code into hijacked processes in order to evade process-based defenses as well as possibly elevate privileges. Thread Execution Hijacking is a method of executing arbitrary code in the address space of a separate live process. Thread Execution Hijacking is commonly performed by suspending an existing process then unmapping/hollowing its memory, which can then be replaced with malicious code or the path to a DLL. A handle to an existing victim process is first created with native Windows API calls such as <codeOpenThread</code.
Mitigations: Behavior Prevention on Endpoint
MITRE ATT&CK reference →Obfuscated Files or Information T1027 Stealth
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses. Payloads may be compressed, archived, or encrypted in order to avoid detection. These payloads may be used during Initial Access or later to mitigate detection. Sometimes a user's action may be required to open and Deobfuscate/Decode Files or Information for User Execution. The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.
Mitigations: User Training, Behavior Prevention on Endpoint, Antivirus/Antimalware, Audit
MITRE ATT&CK reference →Masquerading T1036 Stealth
Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names. Renaming abusable system utilities to evade security monitoring is also a form of Masquerading.
Mitigations: User Training, Execution Prevention, Code Signing, Behavior Prevention on Endpoint, User Account Management, Restrict File and Directory Permissions
MITRE ATT&CK reference →MITRE ATT&CK techniques attributed to Rhysida across its recorded activity. They describe the group overall, not any single incident.
Tooling observed in Rhysida operations
- PowerView
- WinSCP
- PsExec
- WMIC
- Impacket
- AnyDesk
Software reported in use by Rhysida. Most are legitimate administration or transfer utilities; their presence in an environment is a signal to investigate, not proof of compromise.
Indicators of compromise
- f6e5f0ed974c89e2b4a47989fc987c79
- 6742fdde9d5fde37ac5a9c9cbb1f691f
- 7cfba113342f78b5909f606c26fc1dc4
- 6dd8c26f64df37d0c7645b63c9bba51f
- 0cf5491278c7d87e8c3fc88c7f9f26ff
- d86383882515b7a9218d5f69924feadf
Showing a sample of 28 MD5 on file. Hashes and network indicators published for Rhysida. Leak-site addresses are deliberately excluded. Indicators age quickly — treat a match as a starting point for investigation, and an absence of matches as no assurance.
Threat Actor Analysis
Rhysida is a ransomware threat group that has disclosed 203 victims in publicly accessible leak site data, representing 0.9% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Rhysida in our dataset dates to January 2024.
Geographically, Rhysida has targeted organisations in 23 countries. The most frequently targeted nation is United States with 122 victim organisations. Other heavily targeted nations include Canada, United Kingdom, Germany.
Industry-wise, Rhysida shows a concentration in the Healthcare, Education, Business Services sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime — conditions that increase ransom payment likelihood.
Like most modern ransomware operations, Rhysida likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.
Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 100 most recent of the 203 disclosures we hold for this group; use the link beneath it to page through all of them.
Recent Victim Disclosures (showing 100 of 203)
| # | Organization | Country | Sector | Date |
|---|---|---|---|---|
| 1 | Szechenyi Programiroda Nonprofit Kf | 🇭🇺 Hungary | Other | Sep 1, 2026 |
| 2 | Berlin, Germany | 🇩🇪 Germany | — | Aug 28, 2026 |
| 3 | Valley Health Team | — | Healthcare | Aug 28, 2026 |
| 4 | CRI Electric crielectric.com | 🇺🇸 United States | Energy & Utilities | Aug 22, 2026 |
| 5 | Battle Creek Public Schools battlecreekschools.net | 🇺🇸 United States | Education | Aug 21, 2026 |
| 6 | Fairview Dental Group | 🇺🇸 United States | Healthcare | Aug 21, 2026 |
| 7 | Pierce Township piercetownship.org | 🇺🇸 United States | Government & Defense | Aug 14, 2026 |
| 8 | SIA Medical Centre siamed.com.au | 🇱🇻 Latvia | Healthcare | Aug 13, 2026 |
| 9 | Lawson Roofing | — | Construction | Jun 18, 2026 |
| 10 | IDS Group idsgi.com | 🇺🇸 United States | — | May 25, 2026 |
| 11 | Landeshauptstadt Stuttgart stuttgart.de | 🇩🇪 Germany | Public Sector | May 19, 2026 |
| 12 | Tower View Primary School towerview.staffs.sch.uk | 🇬🇧 United Kingdom | Education | May 15, 2026 |
| 13 | Stelia North America | 🇺🇸 United States | Manufacturing | Apr 27, 2026 |
| 14 | Southold Town Senior ServicesSouthold Police Department | — | Public Sector | Mar 2, 2026 |
| 15 | Rohner rohnerspraybooths.com | 🇨🇭 Switzerland | Manufacturing | Feb 23, 2026 |
| 16 | Cheyenne & Arapaho Tribes cheyenneandarapaho-nsn.gov | 🇺🇸 United States | Public Sector | Feb 17, 2026 |
| 17 | Phoenix Art Museum phxart.org | 🇺🇸 United States | Education | Feb 12, 2026 |
| 18 | Leading Edge Speciali | — | Business Services | Feb 6, 2026 |
| 19 | Lakeside Union School District lsusd.net | 🇺🇸 United States | Education | Feb 4, 2026 |
| 20 | Elabs elabs.de | 🇸🇪 Sweden | Technology | Feb 2, 2026 |
| 21 | MACT Health Board macthealth.org | 🇺🇸 United States | Healthcare | Jan 29, 2026 |
| 22 | Cytek Biosciences cytekbio.com | 🇺🇸 United States | Healthcare | Jan 25, 2026 |
| 23 | Jet-care International jet-care.com | 🇨🇭 Switzerland | Transportation/Logistics | Jan 21, 2026 |
| 24 | Charles Leonard Steel Services charlesleonardsteelservices.com | 🇺🇸 United States | Manufacturing | Jan 6, 2026 |
| 25 | Falk, Waas, Hernandez, Cortina, Solomon & Bonner Overview Metrics falkwaas.com | 🇺🇸 United States | Business Services | Dec 30, 2025 |
| 26 | Larry Pitt & Associates larrypitt.com | 🇺🇸 United States | Business Services | Dec 19, 2025 |
| 27 | YOKOSUKA GAKUIN yokosuka-gakuin.ac.jp | 🇯🇵 Japan | Education | Dec 15, 2025 |
| 28 | ***** *********** | — | — | Dec 13, 2025 |
| 29 | United Keetoowah Band of Cherokee Indians in Oklahoma ukbb-nsn.gov | 🇺🇸 United States | Public Sector | Dec 12, 2025 |
| 30 | Harbour Town Doctors harbourtowndoctors.com.au | 🇦🇺 Australia | Healthcare | Dec 11, 2025 |
| 31 | Woodard, Emhardt, Henry, Reeves & Wagner, LLP uspatent.com | 🇺🇸 United States | Business Services | Dec 11, 2025 |
| 32 | Kane's Furniture kanes.com | 🇺🇸 United States | Consumer Services | Dec 7, 2025 |
| 33 | SODISE sodise.com | 🇫🇷 France | Business Services | Dec 6, 2025 |
| 34 | Bo Beuckman Ford bobeuckmanford.com | 🇺🇸 United States | Consumer Services | Dec 3, 2025 |
| 35 | Cleveland County Sheriff's Office cso-ok.us | 🇺🇸 United States | Public Sector | Dec 2, 2025 |
| 36 | AGS | — | — | Nov 26, 2025 |
| 37 | Marlex Human Capital marlexhc.pl | 🇵🇱 Poland | Business Services | Nov 25, 2025 |
| 38 | Collge Superieur De Montreal csmontreal.ca | 🇨🇦 Canada | Education | Nov 24, 2025 |
| 39 | St. Joseph's Healthcare Hamilton stjoes.ca | 🇨🇦 Canada | Healthcare | Nov 22, 2025 |
| 40 | Wachusett School District MA wrsd.net | 🇺🇸 United States | Education | Nov 21, 2025 |
| 41 | Smoll & Banning, CPAs smollandbanning.com | 🇺🇸 United States | Financial Services | Nov 18, 2025 |
| 42 | Heart South Cardiovascular Group heartsouthpc.com | 🇺🇸 United States | Healthcare | Nov 10, 2025 |
| 43 | LMHT Associates lmht.com | 🇺🇸 United States | — | Nov 10, 2025 |
| 44 | KISS FM kissfm.es | 🇪🇸 Spain | Telecommunication | Nov 5, 2025 |
| 45 | Automated Logistics Systems automatedlogistics.com | 🇺🇸 United States | Transportation/Logistics | Nov 4, 2025 |
| 46 | Invacare invacare.com | 🇺🇸 United States | Healthcare | Nov 4, 2025 |
| 47 | Spindletop Center spindletop.org | 🇺🇸 United States | Healthcare | Oct 30, 2025 |
| 48 | Bellflower Unified School District bellsd.org | 🇺🇸 United States | Education | Oct 28, 2025 |
| 49 | Gemini Group geminigroup.net | 🇺🇸 United States | — | Oct 28, 2025 |
| 50 | Abilene Family Medical Associates abilenedocs.com | 🇺🇸 United States | Healthcare | Oct 27, 2025 |
| 51 | Peraso perasotech.com | 🇨🇦 Canada | Technology | Oct 21, 2025 |
| 52 | GEIGER geiger-antriebstechnik.de | 🇩🇪 Germany | Business Services | Oct 17, 2025 |
| 53 | Hematology Oncology Consultants hocpc.com | 🇺🇸 United States | Healthcare | Oct 17, 2025 |
| 54 | Sibbalds sibbalds.co.uk | 🇬🇧 United Kingdom | Business Services | Oct 16, 2025 |
| 55 | Tex-Tube tex-tube.com | 🇺🇸 United States | Manufacturing | Oct 15, 2025 |
| 56 | Furuno Electric furuno.com | 🇯🇵 Japan | Technology | Oct 13, 2025 |
| 57 | Sdii Global sdii-global.com | 🇺🇸 United States | Business Services | Oct 9, 2025 |
| 58 | JASCO Applied Sciences jasco.com | 🇨🇦 Canada | Technology | Oct 7, 2025 |
| 59 | Medstar Health medstarhealth.org | 🇺🇸 United States | Healthcare | Oct 4, 2025 |
| 60 | Peavey Electronics Corporation peavey.com | 🇺🇸 United States | Manufacturing | Sep 29, 2025 |
| 61 | The Maryland Department of Transportation | 🇺🇸 United States | Public Sector | Sep 24, 2025 |
| 62 | Coastal Pacific Xpress coastalpacificxpress.com | 🇨🇦 Canada | Transportation/Logistics | Sep 10, 2025 |
| 63 | Elite Trailers elitetrailers.com | 🇺🇸 United States | Manufacturing | Sep 5, 2025 |
| 64 | Firelands Scientific firelandsscientific.com | 🇺🇸 United States | — | Aug 28, 2025 |
| 65 | ZCORP zcorp.com | 🇺🇸 United States | Technology | Aug 27, 2025 |
| 66 | Elkhart Independent School District elkhartisd.net | 🇺🇸 United States | Education | Aug 20, 2025 |
| 67 | Trans-Tex trans-tex.pl | 🇵🇱 Poland | Manufacturing | Aug 12, 2025 |
| 68 | Alascom Alascom.it | 🇮🇹 Italy | Technology | Aug 10, 2025 |
| 69 | Cookeville Regional Medical Center crmchealth.org | 🇺🇸 United States | Healthcare | Aug 2, 2025 |
| 70 | First Baptist Church of Hammond fbchammond.org | 🇺🇸 United States | — | Jul 29, 2025 |
| 71 | Cardinal Services cardinalservices.org | 🇺🇸 United States | Business Services | Jul 15, 2025 |
| 72 | Florida Hand Center flhandcenter.com | 🇺🇸 United States | Healthcare | Jul 8, 2025 |
| 73 | Welthungerhilfe welthungerhilfe.de | 🇩🇪 Germany | Public Sector | Jun 29, 2025 |
| 74 | Coreix coreix.net | 🇬🇧 United Kingdom | Technology | Jun 18, 2025 |
| 75 | CNPC USA cnpc.com.cn | 🇺🇸 United States | Energy | Jun 16, 2025 |
| 76 | Hudson River Housing hudsonriverhousing.org | 🇺🇸 United States | Public Sector | Jun 7, 2025 |
| 77 | Cator Ruma & Associates catorruma.com | 🇺🇸 United States | Construction | May 28, 2025 |
| 78 | Carrera Chevrolet carrera.com.br | 🇧🇷 Brazil | Manufacturing | May 26, 2025 |
| 79 | Florida Lung floridalung.com | 🇺🇸 United States | Healthcare | May 20, 2025 |
| 80 | Termolar termolar.com.br | 🇧🇷 Brazil | Manufacturing | May 18, 2025 |
| 81 | Sao Camilo Cachoeiro de Itapemirim saocamilo.br | 🇧🇷 Brazil | Education | May 14, 2025 |
| 82 | Mountain View Mushrooms mountainviewmushrooms.com | 🇺🇸 United States | Agriculture and Food Production | May 9, 2025 |
| 83 | Mediprobe Research mediprobe.com | 🇨🇦 Canada | Healthcare | May 5, 2025 |
| 84 | Kalin Hobeltechnik kaelin-hobeltechnik.ch | 🇨🇭 Switzerland | Manufacturing | May 3, 2025 |
| 85 | Government of Peru Gob.pe | 🇵🇪 Peru | Public Sector | May 1, 2025 |
| 86 | Coop UQAM coopuqam.com | 🇨🇦 Canada | Education | Apr 29, 2025 |
| 87 | LaBella Associates labellapc.com | 🇺🇸 United States | Business Services | Apr 28, 2025 |
| 88 | MDB | 🇺🇸 United States | Technology | Apr 26, 2025 |
| 89 | Milicic milicic.com.ar | 🇦🇷 Argentina | Construction | Apr 23, 2025 |
| 90 | Acos Favorit acosfavorit.com.br | 🇳🇴 Norway | Manufacturing | Apr 22, 2025 |
| 91 | Oregon Department of Environmental Quality oregon.gov | 🇺🇸 United States | Public Sector | Apr 15, 2025 |
| 92 | Dimension Composite dimensioncomposite.com | 🇨🇦 Canada | Manufacturing | Apr 12, 2025 |
| 93 | Swiss Capitals Group swisscapitals.com | 🇨🇭 Switzerland | Financial Services | Apr 6, 2025 |
| 94 | Clarity Ventures clarity-ventures.com | 🇺🇸 United States | Technology | Apr 2, 2025 |
| 95 | Forrest City School District mustang.grsc.k12.ar.us | 🇺🇸 United States | Education | Mar 28, 2025 |
| 96 | Senior Support Services cphcare.ca | 🇨🇦 Canada | Healthcare | Mar 27, 2025 |
| 97 | Okeene Elementary School okeene.k12.ok.us | 🇺🇸 United States | Education | Mar 25, 2025 |
| 98 | Ted Hosmer Enterprises tedhosmer.com | 🇺🇸 United States | Consumer Services | Mar 18, 2025 |
| 99 | Cothron's Security Professionals cothrons.com | 🇺🇸 United States | Business Services | Mar 14, 2025 |
| 100 | British virgin islands London Office bvi.org.uk | 🇬🇧 United Kingdom | Public Sector | Mar 9, 2025 |
Frequently Asked Questions
What is Rhysida ransomware?
Rhysida is a ransomware threat group that has claimed 203 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.
How many victims has Rhysida attacked?
Rhysida has claimed 203 victims in our database, representing 0.9% of all tracked ransomware attacks. The most targeted countries are United States, Canada, United Kingdom, Germany.
Which countries does Rhysida target?
Rhysida has attacked organizations in 23 countries. The top targeted countries are: United States, Canada, United Kingdom, Germany.
Which industries does Rhysida target?
Rhysida most frequently targets the Healthcare, Education, Business Services sectors based on victim disclosures in our database.
Is Rhysida still active?
Rhysida's most recent victim disclosure in our database was on September 1, 2026. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.