Compiled from this incident record and the threat intelligence profile for Rhysida. Figures and technique mappings are quoted from the source data, not inferred.
Rhysida listed NEAD Pro on its dark web leak site on 24 September 2026. NEAD Pro is a multidisciplinary firm based in Italy that provides legal, tax, bankruptcy, and accounting consulting services.
About NEAD Pro
NEAD Pro Nead Pro is a professional multidisciplinary firm based in Gorizia and Udine, Italy, that provides legal, tax, bankruptcy, and accounting consulting services.What it is: a network share belonging to two Italian professional firms located at Via Roma 20, Gorizia (Friuli-Venezia Giulia):NEAD SRL (NORTH EAST ADVISORS S.R.L.) - an accounting firm, dottore commercialista, P.IVA 01114220310, REA GO-72906;NEAD PRO - PROFESSIONISTI RIUNITI - a law firm, P.IVA 01157140318.Volume: ~575,000 files / ~253 GB. The root contains a single branch Nuova directory\NEAD\ (plus an empty Documenti folder and a scatter of PDF scans at the root level).Structure and contents:Branch Volume ContentsNEAD PRO SITE - Documenti 231,137 files / 193.5 GB Law firm: 03.PRATICHE (46,620 files: CIVILE 9,665, PENALE 537, SOVRAINDEBITAMENTO 1,208), 04. INCARICHI (85,321: FALLIMENTI 22,492, ESECUZIONI 28,509, ADS 14,547, TRUST, CURATELE), SEGRETERIA with CREDENZIALI VARIE.xlsx (~40 firm accounts: SPID, PEC, banks, 2 cards with full PAN+CVC, safe code), bank scans (BANCOMAT PIN, BCC agreements)NEAD SRL SITE - Documenti 101,125 / 55.3 GB Accounting firm: 03.CLIENTI - 199 active + 184 former client folders (730, CU, F24, contracts), 44 private SOGEI Entratel .P12 keys (signing clients' tax returns), ISA/IRAP tax filings 2019�2020, client master data, Account.xlsxPRIMA NOTA - Documenti 1,885 / 871 MB Cash books 2019�2026 (21 xlsx): CASSA / CONTO CORRENTE / POS / CARTA / SISTERPOWERBI - Documenti 548 / 627 MB 37 financial BI models .pbix (BI_ISIDE, BI_NEAD, ATHENA, PNAI)ARCHIVIO 921 / 2.6 GB MPS bank statements 2020�2024, NEAD SRL account closure, firm mail archivePOSTA SARDAMAR / PANEGIOCHI / ISIDE / ADMIN SRL ~165+ / ~174 MB Client and firm mail: IVECO Capital leasing, accertamento Agenzia Entrate, Capitaneria di Porto, verbali poliziaES. IMM. 112-2024 10 files Real-estate enforcement proceedings (Tribunale di Gorizia): bank statements and CIE (ID cards) of auction participantsNEAD root ~85 PDF / 127 MB Scanned bank statements, F24 forms, IPZS envelope with the PIN/PUK of a CIE cardMost sensitive data: client dossiers with tax codes (codici fiscali), court case files (civil/criminal/bankruptcy), medical documents (Art. 9 GDPR), the firm's credential database with full PAN+CVC of two cards and the safe code, 52 Entratel electronic signature keys, ~100 SEPA mandates with IBANs and signatures, client PST archives (7.5 GB), a client's Huawei phone backup (Facebook/Gmail/Telegram databases), passports of foreign shareholders. More
Source record: ransomware.live
About the Rhysida group
Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks and Cobalt Strike to breach the targets' networks and deploy their payloads. The group threatens to publicly distribute exfiltrated data if the ransom is not paid, and it's worth mentioning that Rhysida is still in the early stages of development. The ransomware leaves PDF notes in the affected folders, instructing victims to contact the group through its portal, and payment is made via Bitcoin. After encryption, the ransomware appends the extension '.ryshida' to encrypted files. Source: https://github.com/crocodyli/ThreatActors-TTPs Rhysida has listed 283 victims since June 2023.
How Rhysida is documented to operate
Phishing
T1566
Initial Access
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns. Adversaries may send victims emails containing malicious attachments or links, typically to execute malicious code on victim systems. Phishing may also be conducted via third-party services, like social media platforms.
Mitigations:
Network Intrusion Prevention, Restrict Web-Based Content, User Training, Antivirus/Antimalware, Software Configuration, Audit
MITRE ATT&CK reference →
Command and Scripting Interpreter
T1059
Execution
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell. There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic.
Mitigations:
Restrict Web-Based Content, Limit Software Installation, Execution Prevention, Code Signing, Behavior Prevention on Endpoint, Privileged Account Management
MITRE ATT&CK reference →
Shared Modules
T1129
Execution
Adversaries may execute malicious payloads via loading shared modules. Shared modules are executable files that are loaded into processes to provide access to reusable code, such as specific custom functions or invoking OS API functions (i.e., Native API). Adversaries may use this functionality as a way to execute arbitrary payloads on a victim system. For example, adversaries can modularize functionality of their malware into shared objects that perform various functions such as managing C2 network communications or execution of specific actions on objective. The Linux & macOS module loader can load and execute shared objects from arbitrary local paths.
Mitigations:
Execution Prevention
MITRE ATT&CK reference →
Registry Run Keys / Startup Folder
T1547.001
Persistence
Privilege Escalation
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
MITRE ATT&CK reference →
Process Injection
T1055
Stealth
Privilege Escalation
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process. There are many different ways to inject code into a process, many of which abuse legitimate functionalities.
Mitigations:
Behavior Prevention on Endpoint, Privileged Account Management
MITRE ATT&CK reference →
MITRE ATT&CK techniques attributed to Rhysida across its recorded activity, not a finding about how NEAD Pro was reached.
Vulnerabilities Rhysida is recorded exploiting
5 of these 5 are in the CISA Known Exploited Vulnerabilities catalog, 5 of them recorded by CISA as used in ransomware campaigns. CVEs attributed to Rhysida across its reported activity. There is no indication that any of these was involved in the NEAD Pro incident — the source data does not record an entry point.