Rhysida Ransomware Explained: TTPs, IOCs and How to Defend in 2026
جدول المحتويات
- 1. What is Rhysida?
- 2. Rhysida ransomware in numbers
- 3. The Rhysida ransomware timeline
- 4. How a Rhysida ransomware attack works
- The traits of a Rhysida attack
- 5. Case studies: Rhysida ransomware victims
- When a capital city was put up for auction...
- When the British Library went dark...
- When a German city said nothing...
- When an airport operator was hit...
- 6. Can Rhysida ransomware be decrypted?
- 7. Defending against the Rhysida ransomware group
- Enabling multi-factor authentication (MFA) everywhere
- Watching for exposed credentials
- Closing gaps in your external exposure
- اتباع قاعدة 3-2-1
- Segmenting your network
- عدم الدفع
- إعداد خطة الاستجابة للحوادث
- إليك
Rhysida threat actors posted a leak-site entry titled simply “Berlin, Germany” on August 28, 2026. The entry claimed 5.79 terabytes of data lifted from the German capital’s state network, spanning roughly 1.44 million files. The group demanded 30 bitcoin, worth around €2 million, and set a seven-day countdown before it said it would start selling. Der Spiegel first reported the attribution on the evening of August 28, and Berlin’s Governing Mayor confirmed the extortion attempt after an emergency Senate session, saying the state would not be blackmailed.
It’s the largest claim Rhysida has ever made against a European public body, and it lands on the back of a steady three-year run. The group has now named close to 300 victims since 2023 across 39 countries, including the British Library, the Port of Seattle, the Chilean Army, and the city administration of Stuttgart.
This guide covers how Rhysida attacks work, the TTPs and IOCs that CISA has documented, whether the malware can still be decrypted for free, and the specific defenses that stop the attack chain at its weakest point.
1. What is Rhysida?
Rhysida is a ransomware-as-a-service (RaaS) group that emerged in May 2023.
Affiliates use Rhysida’s malware to steal and encrypt sensitive data, and any ransom paid is split between the affiliate and the core group. Demands have ranged from a few hundred thousand euros to several million.
Rhysida sits alongside other established RaaS players such as لوك بيت, رانسوم هاب, و أكيرا, though it operates at a fraction of their volume.
What makes the group distinctive is how it presents itself. The ransom note opens with an automated alert from “cybersecurity team Rhysida,” and describes the encryption key it is selling as the first step in the victim’s recovery. Tripwire noted that it even signs off with “Best regards.” Security researchers at Check Point and eSentire have documented technical and operational overlaps with the now-defunct Vice Society group, which went quiet at almost exactly the moment Rhysida appeared.

Rhysida takes its name from a genus of centipede, and its Tor site is built around that imagery alongside a token field. Victims enter the unique code from their ransom note to open a dedicated contact form. The homepage lists current auctions and a running victim count.
That auction model is worth noting. Rather than a flat demand, Rhysida frequently puts stolen data up for sale with a minimum bid and a deadline, as it did with Berlin.
In November 2023, the FBI, CISA and the Multi-State Information Sharing and Analysis Center (MS-ISAC) released a joint advisory titled #StopRansomware: Rhysida Ransomware (AA23-319A), with indicators of compromise (IOCs) to show when a system has been breached. It was refreshed in April 2025 with new indicators and the outdated ones stripped out.
2. Rhysida ransomware in numbers
Rhysida has kept a remarkably even pace since 2023, avoiding the burnout that ends most RaaS operations inside eighteen months.
Here are 6 insights into the Rhysida world.
- Close to 300 named victims: Breachsense counted 295 organizations on the leak site as of September 1, 2026, with 54 of those posted in the last twelve months. Ransomware.live listed 280 as of August 29, and Ransom-DB had 265 in February 2026. Trackers differ depending on how they collect.
- Roughly 7 victims a month: Modest next to Akira or Qilin, but consistent. Ransom-DB observed the group posting victims on an almost daily basis through December 2025, with that momentum carrying into 2026.
- Around half of all victims are US-based: Ransom-DB put the figure at 49.4% in early 2026. Europe is where the growth is.
- Education and healthcare lead the sector count: 56 and 41 victims respectively, out of the 199 Breachsense could classify. Treat that as the shape of the targeting rather than a full census.
- Germany accounts for nine victims: Leak-site monitoring put the German total at nine as of August 29, 2026. Small in absolute terms, but they include a state government and two city-level targets.
- A third of victims had credentials exposed first: Breachsense found that 33.6% of Rhysida victims with an identifiable domain had employee credentials appear in a breach in the twelve months before they were named. Nobody has established that those credentials were the way in, but the correlation is hard to ignore.
For wider context, Germany was the fourth most-targeted country in the world for ransomware in the first half of 2026, with 176 claimed victims across all groups. Switzerland recorded 35 and Austria 29.
3. The Rhysida ransomware timeline

4. How a Rhysida ransomware attack works
Here are the technical stages of a Rhysida هجوم برامج الفدية, ، وفقًا ل سايزا.
- الوصول الأولي: Rhysida affiliates log in rather than break in. The primary route is valid compromised credentials against external-facing services such as VPNs without multi-factor authentication (MFA). Spear التصيد الاحتيالي is also used, as is the Zerologon vulnerability (CVE-2020-1472) where it remains unpatched.
- المثابرة والاكتشاف: The group escalates privileges and harvests domain credentials using
ntdsutil.exeto extract the NTDS database. Network mapping is done with living-off-the-land tooling and utilities such as Advanced IP Scanner, with remote access maintained through legitimate software like AnyDesk. - التهرب من الدفاع Affiliates clear logs and terminate security processes to buy time for lateral movement.
- الاستنزاف والتأثير: Data is pulled out before anything is encrypted. In the Berlin case, forensic investigators traced exfiltration to a five-day window between August 7 and August 12, 2026. The affected systems weren’t isolated until August 14.
- تشفير البيانات: The payload is deployed with PsExec and encrypts files using a 4096-bit RSA key with the ChaCha20 algorithm. Rhysida uses intermittent encryption, only partially encrypting each file to work faster. Encrypted files get the
.rhysidaextension and a ransom note namedCriticalBreachDetected.pdfis dropped.
One detail from the CISA advisory is worth putting straight into your detection rules: the contents of the ransom note are embedded as plain text inside the ransomware binary. That gives defenders a straightforward opportunity to deploy string-based detection for alerting on evidence of the note. Fortinet’s incident response team has also published a full intrusion walkthrough with threat-hunting queries.
You can view the full list of MITRE ATT&CK tactics on CISA’s النشرة الأمنية.
The traits of a Rhysida attack
Here are some of the tactics, techniques, and procedures (TTPs) that show up again and again.
- باستخدام نموذج الابتزاز المزدوج: Rhysida encrypts data and steals it, then threatens publication as a second lever. CISA maps this to MITRE technique T1657.
- Auctioning rather than demanding: Stolen data is often listed for sale with a minimum bid, which turns a private negotiation into a public countdown.
- Delivering the note as a PDF: Unusual, and possibly deliberate. CISA has suggested the PDF format may indicate the group targets systems that don’t run command-line operating systems.
- Communicating through Onion Mail: Affiliates have been observed creating Onion Mail accounts for victim contact, alongside the Tor portal.
- طلب مدفوعات البيتكوين Victims are directed to send payment to wallet addresses supplied by the threat actors.
- Choosing targets that can’t stay quiet: Municipal governments, hospitals, universities and libraries all face intense public scrutiny the moment a breach becomes known. That scrutiny is the pressure.
5. Case studies: Rhysida ransomware victims
Rhysida برمجيات الفدية can pose a threat to any organization, but the pattern in its victim list is unusually clear. Let’s look at some real-life stories of Rhysida in action, when اليقظة الرقمية فشلت.
When a capital city was put up for auction…
Berlin’s state government spent most of August 2026 trying to contain a breach quietly.
Two Senate departments were disconnected from the state network on August 14 and stayed offline for nine days. Those were Urban Development, Building and Housing, and Mobility, Transport, Climate Protection and Environment. Investigators traced the data exfiltration to August 7 to 12, meaning attackers had roughly a week inside before anyone pulled the plug.
On August 27 the ransom demand arrived. On August 28 Rhysida published the listing: 5.79 terabytes, 1.44 million files, 30 bitcoin minimum bid, one week to pay.
Among the categories the group claims to hold are 80,000 administrative offence proceedings, 46,500 contracts, personal data on 12,076 people, judicial documents, a critical-infrastructure assessment of Berlin’s water supply, and credential files. Berlin has not confirmed any of these figures.
Threat intelligence account FalconFeeds.io flagged the listing on the day it appeared, naming the Senate Department for Urban Development, Building and Housing specifically, whereas Rhysida’s own entry was titled only “Berlin, Germany.”
The knock-on effects were immediate. Around 50,000 households faced delays in housing benefit payments, and by September 1 at least two Senate departments had blocked home office access entirely after passwords for internal specialist applications appeared online. Email access stayed open.
Governing Mayor Kai Wegner confirmed the extortion attempt and stated that Berlin would not be blackmailed, calling the state the victim of a serious crime. The Landeskriminalamt and the public prosecutor opened a criminal investigation alongside federal security authorities.
When the British Library went dark…
In October 2023, Rhysida encrypted the systems of the British Library and exfiltrated several hundred gigabytes of internal data.
The library refused to pay, and the group published the data. Recovery took the institution well over a year, and the incident became one of the most-studied public sector ransomware cases in Europe, largely because the library published an unusually candid post-incident review.
When a German city said nothing…
In May 2026, Rhysida claimed an attack on the city administration of Stuttgart, with a demand of around €330,000, a fraction of what it would later ask Berlin for.
Stuttgart never publicly confirmed that any data had been exfiltrated. This is a useful reminder that a leak-site listing is a claim, not a confirmed breach, and that the two are routinely conflated in reporting.
When an airport operator was hit…
In September 2024, the Port of Seattle, which operates Seattle-Tacoma International Airport, was added to the leak site.
Alongside earlier attacks on the Chilean Army and Prospect Medical Holdings, which affected 17 hospitals and 166 clinics in the US, it demonstrates how far Rhysida is willing to reach into critical infrastructure.
6. Can Rhysida ransomware be decrypted?
Sometimes. This is the part of the Rhysida story most coverage skips, and it comes with real caveats.
In February 2024, researchers from Kookmin University in Seoul and the Korea Internet and Security Agency (KISA) published a paper describing an implementation vulnerability in Rhysida’s encryption.
The malware used a secure random number generator to produce its encryption key. The developers made a mistake in how they implemented it, and the researchers were able to regenerate the generator’s internal state at the moment of infection, reconstruct the key, and work out the order in which files had been encrypted.
KISA released a free decryption tool and a manual. Files it recovers are saved as copies with _dec appended to the filename.
Three caveats matter here.
- It only covers Windows: The tool works against Windows Portable Executable (PE) strains, not everything Rhysida deploys.
- It may already be obsolete: Fabian Wosar of Emsisoft, whose team had found the same flaw privately in May 2023, warned that it would be trivial for the group to patch and that they would likely do so within days of the public disclosure. Avast had independently found it in August 2023.
- Decryption doesn’t undo exfiltration: Even a perfect decryptor does nothing about the copy of your data sitting on a leak site. Under double extortion, recovering your files solves half the problem at most.
If you are dealing with an active Rhysida infection, remove the malware first to avoid reinfection, then try the decryptor on Windows systems. Plan on the assumption that it won’t work.
7. Defending against the Rhysida ransomware group
Rhysida’s attack chain has an obvious weak point: it starts with credentials, not exploits. Here’s how to safeguard your وضع الأمن السيبراني.
Enabling multi-factor authentication (MFA) everywhere
MFA adds a second form of verification on top of the password: a code from an authenticator app, a fingerprint, or a hardware token.
Rhysida’s most commonly documented entry point is an external-facing remote service, usually a VPN, that doesn’t have it. CISA, the FBI and MS-ISAC put MFA for all services at the top of their Rhysida mitigations, singling out webmail, VPN and accounts that reach critical systems. If you fix one thing on this list, fix that one.
Watching for exposed credentials
A third of Rhysida’s victims had employee credentials surface in a breach during the year before they were named on the leak site.
Nobody has proven those credentials were the route in. But they were sitting in public, they belonged to organizations that were subsequently compromised, and they were findable before the attack rather than after it.
Credential Intelligence monitoring identifies exposed email and password pairs tied to your domains so you can force a reset before someone else uses them.
Closing gaps in your external exposure
Patch Zerologon (CVE-2020-1472) if you somehow still haven’t, and get a complete picture of what of yours is reachable from the internet.
أن إدارة سطح الهجوم الخارجي (EASM) tool such as سايبل أنجل maps your exposed assets, including the shadow IT nobody remembers deploying, so you can fix weaknesses before threat actors find them.
You can also use الويب المظلم monitoring to pick up mentions of your organization on leak sites and underground forums, which in Berlin’s case would have been the difference between finding out on August 28 and finding out from Der Spiegel.
اتباع قاعدة 3-2-1
The standard backup guidance still holds:
- 3 أضعاف نسخ الملفات المهمة
- أنواع وسائط اثنان لتخزين هذه الملفات
- 1x offline/offsite copy of these files
Good backups support حماية البيانات and system recovery. They do not protect you from publication, which is the half of double extortion that backups can’t touch.
Segmenting your network
Berlin’s response was to cut network segments department by department, then reconnect each one only after it passed inspection. That took nine days. By then, forensic investigators had traced the seven-day gap between first detection and isolation as the window that mattered.
Segmentation designed before an incident makes that process faster and limits how far one compromised department can spread.
عدم الدفع
The FBI, CISA and European authorities all advise against paying, and Berlin followed that line publicly and immediately.
Paying doesn’t guarantee your data is deleted, doesn’t guarantee it isn’t resold, and marks your organization as a target that pays. Report the attack to law enforcement instead.
إعداد خطة الاستجابة للحوادث
Have a plan for if your organization is compromised by Rhysida. Identify key team members and roles, and create a step-by-step process for detecting, containing, and mitigating incidents.
Include a communications plan. Berlin was criticised for how little it said in the first two weeks, and the information vacuum was filled by the attackers’ own leak-site claims.
إليك
Rhysida will not out-produce Qilin or Akira on volume, and it doesn’t try to. It goes after organizations that can’t negotiate in private, and it has now proven it can reach a European state government.
The good news is that the attack chain is stoppable early. MFA on every external service, visibility over your exposed assets, and monitoring for credentials that have already leaked will close the door Rhysida walks through most often.
With the right controls and tools such as سايبل أنجل in place, you can find your exposure before the threat actors do.
