Overview

Platforms: Windows · Linux · VMware ESXi
Variants: Windows encryptor · Linux/ESXi encryptor
Extensions: .rhysida
ATT&CK software: PsExec (S0029) · Impacket (S0357)
Initial access: Valid Accounts · Exploit Public-Facing Application · Phishing
Top countries: US · CA · GB · DE · IT
Observed sectors: Education · Healthcare · Professional Services · Government & Defense · Manufacturing
Tracked victims: 286

Attribution

Squeaking Scorpius VERIFIED
Vendor tracking name
Palo Alto Networks Unit 42 tracks the ransomware operation associated with Rhysida as Squeaking Scorpius.
GOLD VICTOR PROBABLE
Probable operator ecosystem
Sophos Counter Threat Unit tracks a cybercriminal cluster as GOLD VICTOR and assesses with moderate confidence that this group shifted from the Vice Society operation toward activity centered on Rhysida ransomware.

Affiliates

No affiliate information available.

Activity

Initial Access

Remote services and valid accounts
Rhysida actors have used compromised valid credentials to authenticate to externally exposed VPN services, particularly where MFA was not enforced.
Phishing
Joint government reporting documents successful phishing as an initial-access method used by Rhysida actors.
Exploitation of known vulnerabilities
Rhysida actors have been observed exploiting known vulnerabilities, including Zerologon CVE-2020-1472.

Recent Observations

Rhysida remains operational
September 2026
Continued activity
Public leak-site monitoring continued to record new Rhysida victim claims in September 2026, while multiple onion services remained reachable.
Rhysida claims Berlin government data
August 2026
Leak-site activity
Rhysida claimed theft of data associated with Berlin's state network and offered the stolen information for auction. The city publicly acknowledged the incident and rejected the extortion demand.
IBM documents Rhysida access and malware ecosystem
June 2026
Ecosystem research
IBM X-Force published long-term research linking Rhysida operations with downloader, crypter and access ecosystems including Endico, Broomstick, Supper and Tomb.
Port of Seattle ransomware attack
August 2024
Confirmed incident
The Port of Seattle publicly attributed its August 2024 ransomware incident to Rhysida and confirmed operational disruption across airport and maritime services.
British Library ransomware attack
October 2023
Confirmed incident
The British Library suffered a major ransomware incident that it later documented as an attack claimed by Rhysida, with data theft and widespread disruption to online systems.
Rhysida operation emerges
May 2023
Emergence
Rhysida emerged as a ransomware-as-a-service operation targeting organizations across education, healthcare, government, manufacturing and technology sectors.

TTPs

ATT&CK coverage: 11 techniques · 9 tactics
T1078 Valid Accounts
VERIFIED
Initial Access / Persistence
Rhysida actors have used compromised valid credentials to authenticate to external-facing VPN services, particularly where multi-factor authentication was not enabled.
T1190 Exploit Public-Facing Application
VERIFIED
Initial Access
Rhysida-associated actors have exploited vulnerable exposed services, including exploitation of CVE-2020-1472 during documented intrusion activity.
T1566 Phishing
VERIFIED
Initial Access
FBI and CISA have observed successful phishing activity associated with Rhysida intrusion operations.
Show more TTPs (8)
T1059.001 PowerShell
VERIFIED
Execution
Rhysida actors use PowerShell for execution, reconnaissance, staging and post-compromise activity.
T1021.001 Remote Desktop Protocol
VERIFIED
Lateral Movement
Rhysida actors use Remote Desktop Protocol for lateral movement inside compromised environments.
VERIFIED
Lateral Movement
Rhysida actors have used PuTTY to establish SSH connections to systems during lateral movement.
VERIFIED
Credential Access
Rhysida actors have used secretsdump and native Windows utilities to obtain the NTDS.dit database and extract Active Directory credential material.
T1219 Remote Access Software
VERIFIED
Command and Control
Rhysida operations have used legitimate remote-access software including AnyDesk to maintain access to compromised systems.
T1070.001 Clear Windows Event Logs
VERIFIED
Defense Evasion
Rhysida actors used wevtutil to clear Windows system, application and security event logs.
T1055.002 Portable Executable Injection
VERIFIED
Privilege Escalation / Defense Evasion
Analysis of Rhysida ransomware identified injection of the ransomware portable executable into running processes.
T1486 Data Encrypted for Impact
VERIFIED
Impact
Rhysida encrypts victim data using ChaCha20 with RSA-4096 key protection and appends the .rhysida extension to encrypted files.

Victims

Berlin state administration CLAIMED
August 2026 Germany Government
Government organization in Germany.
American Addiction Centers CLAIMED
September 2024 United States Healthcare 3 tracker sources
Healthcare organization in United States.
Port of Seattle CONFIRMED
August 2024 United States Transportation & Logistics
Transportation & Logistics organization in United States.
City of Columbus CLAIMED
July 2024 United States Government
Government organization in United States.
MarineMax CLAIMED
March 2024 United States Retail & E-Commerce 3 tracker sources
Retail & E-Commerce organization in United States.
Show more victims (8)
Ann & Robert H. Lurie Children's Hospital of Chicago CLAIMED
January 2024 United States Healthcare 3 tracker sources
Healthcare organization in United States.
Insomniac Games CLAIMED
December 2023 United States Technology 3 tracker sources
Technology organization in United States.
World Council of Churches / Lutheran World Federation CLAIMED
December 2023 Switzerland Non-Profit
Non-Profit organization in Switzerland.
King Edward VII's Hospital CLAIMED
November 2023 United Kingdom Healthcare 3 tracker sources
Healthcare organization in United Kingdom.
British Library CONFIRMED
October 2023 United Kingdom Education
Education organization in United Kingdom.
Prospect Medical Holdings CONFIRMED
August 2023 United States Healthcare
Healthcare organization in United States.
Prince George's County Public Schools CLAIMED
August 2023 United States Education 3 tracker sources
Education organization in United States.
University of the West of Scotland CLAIMED
July 2023 United Kingdom Education 3 tracker sources
Education organization in United Kingdom.

CVEs

Microsoft — Windows Netlogon Remote Protocol
FBI, CISA and MS-ISAC documented Rhysida-associated actors exploiting the Zerologon vulnerability during intrusion activity.
Associated since: May 2023

Infrastructure

Rhysida leak site
Tor-hosted data leak infrastructure used for victim publication, auctions and double-extortion claims.

Timeline

2026-09
Continued active operation
Fresh Rhysida victim claims and reachable leak-site infrastructure continued to be observed in September 2026.
2026-08
Berlin extortion claim
Rhysida claimed a large-scale theft of Berlin government data. Authorities publicly rejected the ransom demand while investigation of the incident continued.
2026-06
Rhysida and Interlock ecosystem overlap documented
IBM X-Force documented shared and related backdoor, downloader and crypter ecosystems surrounding Rhysida and Interlock without attributing both ransomware operations to the same threat actor.
Show more events (5)
2026-05
Rhysida delivery ecosystem affected by Fox Tempest disruption
Microsoft disrupted the Fox Tempest malware-signing service used by Vanilla Tempest in attack chains that included deployment of Rhysida ransomware. The action targeted an enabling service rather than the Rhysida operation itself.
2024-08
Port of Seattle attack
Rhysida attacked Port of Seattle systems, disrupting services associated with Seattle-Tacoma International Airport and other Port operations.
2023-10
British Library attack
A major ransomware attack severely disrupted the British Library, exfiltrated approximately 440 GB of information and was publicly claimed by Rhysida.
2023-06
Vice Society-linked deployment cluster shifts to Rhysida
Sophos observed TAC5279, a cluster previously deploying Vice Society ransomware, begin deploying Rhysida while retaining many of the same intrusion techniques and tools.
2023-05
Rhysida operation emerges
FBI and CISA identify Rhysida ransomware activity beginning in May 2023 across government, education, healthcare, manufacturing and information technology organizations.

Sources

Squeaking Scorpius
Palo Alto Networks Unit 42
Vendor research
Show more sources (24)