Ransomware

Rhysida

First seen: 2023-05 • Status: active

Currently Active Threat

Rhysida is a new ransomware gang that attacked the British Library and several hospitals. They have grown quickly since appearing in 2023.

Overview

Rhysida emerged in 2023 and gained attention for attacking healthcare organizations and the British Library.

How It Spreads

  • Phishing
  • VPN vulnerabilities
  • Valid credentials

What It Does

  • File encryption
  • Data theft
  • Double extortion

Is your business exposed?

Target Platforms

Windows

Detection Tips

  • Monitor for Rhysida signatures
  • Watch for healthcare targeting

MITRE ATT&CK Techniques

T1486, T1567

If You're Infected

  1. 1.

    Check for free decryptor from Kookmin researchers

  2. 2.

    Engage incident response

Related Malware

Blackcat, Lockbit

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required