Overview
Platforms:
Windows · Linux · VMware ESXi
Variants:
Windows encryptor · Linux/ESXi encryptor
Extensions:
.rhysida
ATT&CK software:
PsExec (S0029) · Impacket (S0357)
Initial access:
Valid Accounts · Exploit Public-Facing Application · Phishing
Top countries:
US · CA · GB · DE · IT
Observed sectors:
Education · Healthcare · Professional Services · Government & Defense · Manufacturing
Tracked victims:
286
Attribution
Squeaking Scorpius
VERIFIED
Vendor tracking name
Palo Alto Networks Unit 42 tracks the ransomware operation associated with Rhysida as Squeaking Scorpius.
GOLD VICTOR
PROBABLE
Probable operator ecosystem
Sophos Counter Threat Unit tracks a cybercriminal cluster as GOLD VICTOR and assesses with moderate confidence that this group shifted from the Vice Society operation toward activity centered on Rhysida ransomware.
Affiliates
No affiliate information available.
Activity
Initial Access
Remote services and valid accounts
Rhysida actors have used compromised valid credentials to authenticate to externally exposed VPN services, particularly where MFA was not enforced.
Phishing
Joint government reporting documents successful phishing as an initial-access method used by Rhysida actors.
Exploitation of known vulnerabilities
Rhysida actors have been observed exploiting known vulnerabilities, including Zerologon CVE-2020-1472.
Recent Observations
Rhysida remains operational
September 2026
Continued activity
Public leak-site monitoring continued to record new Rhysida victim claims in September 2026, while multiple onion services remained reachable.
Rhysida claims Berlin government data
August 2026
Leak-site activity
Rhysida claimed theft of data associated with Berlin's state network and offered the stolen information for auction. The city publicly acknowledged the incident and rejected the extortion demand.
IBM documents Rhysida access and malware ecosystem
June 2026
Ecosystem research
IBM X-Force published long-term research linking Rhysida operations with downloader, crypter and access ecosystems including Endico, Broomstick, Supper and Tomb.
Port of Seattle ransomware attack
August 2024
Confirmed incident
The Port of Seattle publicly attributed its August 2024 ransomware incident to Rhysida and confirmed operational disruption across airport and maritime services.
British Library ransomware attack
October 2023
Confirmed incident
The British Library suffered a major ransomware incident that it later documented as an attack claimed by Rhysida, with data theft and widespread disruption to online systems.
Rhysida operation emerges
May 2023
Emergence
Rhysida emerged as a ransomware-as-a-service operation targeting organizations across education, healthcare, government, manufacturing and technology sectors.
TTPs
ATT&CK coverage:
11 techniques
· 9 tactics
T1078
Valid Accounts
VERIFIEDInitial Access / Persistence
Rhysida actors have used compromised valid credentials to authenticate to external-facing VPN services, particularly where multi-factor authentication was not enabled.
T1190
Exploit Public-Facing Application
VERIFIEDInitial Access
Rhysida-associated actors have exploited vulnerable exposed services, including exploitation of CVE-2020-1472 during documented intrusion activity.
T1566
Phishing
VERIFIEDInitial Access
FBI and CISA have observed successful phishing activity associated with Rhysida intrusion operations.
Show more TTPs (8)
T1059.001
PowerShell
VERIFIEDExecution
Rhysida actors use PowerShell for execution, reconnaissance, staging and post-compromise activity.
T1021.001
Remote Desktop Protocol
VERIFIEDLateral Movement
Rhysida actors use Remote Desktop Protocol for lateral movement inside compromised environments.
T1021.004
SSH
VERIFIEDLateral Movement
Rhysida actors have used PuTTY to establish SSH connections to systems during lateral movement.
T1003.003
NTDS
VERIFIEDCredential Access
Rhysida actors have used secretsdump and native Windows utilities to obtain the NTDS.dit database and extract Active Directory credential material.
T1219
Remote Access Software
VERIFIEDCommand and Control
Rhysida operations have used legitimate remote-access software including AnyDesk to maintain access to compromised systems.
T1070.001
Clear Windows Event Logs
VERIFIEDDefense Evasion
Rhysida actors used wevtutil to clear Windows system, application and security event logs.
T1055.002
Portable Executable Injection
VERIFIEDPrivilege Escalation / Defense Evasion
Analysis of Rhysida ransomware identified injection of the ransomware portable executable into running processes.
T1486
Data Encrypted for Impact
VERIFIEDImpact
Rhysida encrypts victim data using ChaCha20 with RSA-4096 key protection and appends the .rhysida extension to encrypted files.
Victims
Berlin state administration
CLAIMED
Government organization in Germany.
American Addiction Centers
CLAIMED
Healthcare organization in United States.
Port of Seattle
CONFIRMED
Transportation & Logistics organization in United States.
City of Columbus
CLAIMED
Government organization in United States.
MarineMax
CLAIMED
Retail & E-Commerce organization in United States.
Show more victims (8)
Ann & Robert H. Lurie Children's Hospital of Chicago
CLAIMED
Healthcare organization in United States.
Insomniac Games
CLAIMED
Technology organization in United States.
World Council of Churches / Lutheran World Federation
CLAIMED
Non-Profit organization in Switzerland.
King Edward VII's Hospital
CLAIMED
Healthcare organization in United Kingdom.
British Library
CONFIRMED
Education organization in United Kingdom.
Prospect Medical Holdings
CONFIRMED
Healthcare organization in United States.
Prince George's County Public Schools
CLAIMED
Education organization in United States.
University of the West of Scotland
CLAIMED
Education organization in United Kingdom.
CVEs
Microsoft
— Windows Netlogon Remote Protocol
FBI, CISA and MS-ISAC documented Rhysida-associated actors exploiting the Zerologon vulnerability during intrusion activity.
Associated since:
May 2023
Infrastructure
Rhysida leak site
Tor-hosted data leak infrastructure used for victim publication, auctions and double-extortion claims.
Timeline
2026-09
Continued active operation
Fresh Rhysida victim claims and reachable leak-site infrastructure continued to be observed in September 2026.
2026-08
Berlin extortion claim
Rhysida claimed a large-scale theft of Berlin government data. Authorities publicly rejected the ransom demand while investigation of the incident continued.
2026-06
Rhysida and Interlock ecosystem overlap documented
IBM X-Force documented shared and related backdoor, downloader and crypter ecosystems surrounding Rhysida and Interlock without attributing both ransomware operations to the same threat actor.
Show more events (5)
2026-05
Rhysida delivery ecosystem affected by Fox Tempest disruption
Microsoft disrupted the Fox Tempest malware-signing service used by Vanilla Tempest in attack chains that included deployment of Rhysida ransomware. The action targeted an enabling service rather than the Rhysida operation itself.
2024-08
Port of Seattle attack
Rhysida attacked Port of Seattle systems, disrupting services associated with Seattle-Tacoma International Airport and other Port operations.
2023-10
British Library attack
A major ransomware attack severely disrupted the British Library, exfiltrated approximately 440 GB of information and was publicly claimed by Rhysida.
2023-06
Vice Society-linked deployment cluster shifts to Rhysida
Sophos observed TAC5279, a cluster previously deploying Vice Society ransomware, begin deploying Rhysida while retaining many of the same intrusion techniques and tools.
2023-05
Rhysida operation emerges
FBI and CISA identify Rhysida ransomware activity beginning in May 2023 across government, education, healthcare, manufacturing and information technology organizations.
Sources
#StopRansomware: Rhysida Ransomware
CISA / FBI / MS-ISAC
Same threats, different ransomware
Sophos X-Ops
Show more sources (24)
Exposing Fox Tempest: A malware-signing service operation
Microsoft Threat Intelligence
Vendor research
Port Cyberattack Archive
Port of Seattle
Learning Lessons from the Cyber-Attack
British Library
Rhysida ransomware tracker
Invaders Cybersecurity
Rhysida ransomware operation tracker
Ransomware.live
Investigating the New Rhysida Ransomware
FortiGuard Labs
British Library Cyber Incident Review
British Library
British Library cyber incident review
British Library
Prospect Medical Holdings cyber incident findings
Connecticut Office of the Attorney General
Insomniac Games alerts employees hit by ransomware data breach
BleepingComputer
Chicago children's hospital data breach
The Record
City of Columbus ransomware data breach
BleepingComputer
MarineMax cyber incident and data theft
The Record
PGCPS cyber notice
Prince George's County Public Schools
Rhysida ransomware gang hits King Edward VII's Hospital
Computer Weekly
American Addiction Centers data breach
The Record