Rhysida — Ransomware Profile
Rhysida is a ransomware-as-a-Service operation that emerged in 2023, notably attacking government and healthcare sectors including UK NHS trusts.Also tracked as
Vice Society (operational successor / shared operators), Rhysida ransomware
Tools & malware
- AnyDesk remote access tool
- Cobalt Strike post-exploitation/C2
- ntdsutil credential dumping (NTDS.dit)
- PortStarter backdoor (Go script)
- PowerView AD reconnaissance
- PsExec lateral movement / execution
- Rhysida ransomware/encryptor
- SILENTKILL PowerShell defense-evasion script
- SystemBC proxy/backdoor implant
Recent claimed victims
- Lawson Roofing 2026-06-18
- IDS Group 2026-05-25
- Landeshauptstadt Stuttgart 2026-05-19
- Tower View Primary School 2026-05-15
- Stelia North America 2026-04-27
- Southold Town Senior ServicesSouthold Police Department 2026-03-02
- Rohner 2026-02-23
- Cheyenne & Arapaho Tribes 2026-02-17
- Phoenix Art Museum 2026-02-12
- Leading Edge Speciali 2026-02-06
- Lakeside Union School District 2026-02-04
- Elabs 2026-02-02
- MACT Health Board 2026-01-29
- Cytek Biosciences 2026-01-25
- Jet-care International 2026-01-21
- Charles Leonard Steel Services 2026-01-06
- Falk, Waas, Hernandez, Cortina, Solomon & Bonner Overview Metrics 2025-12-30
- Larry Pitt & Associates 2025-12-19
- YOKOSUKA GAKUIN 2025-12-15
- United Keetoowah Band of Cherokee Indians in Oklahoma 2025-12-12
- Woodard, Emhardt, Henry, Reeves & Wagner, LLP 2025-12-11
- Harbour Town Doctors 2025-12-11
- Kane's Furniture 2025-12-07
- SODISE 2025-12-06
- Bo Beuckman Ford 2025-12-03
Vendor research
- #StopRansomware: Rhysida Ransomware (AA23-319A) CISA / FBI / MS-ISAC
- The Rhysida Ransomware: Activity Analysis and Ties to Vice Society Check Point Research
- Ransomware Spotlight: Rhysida Trend Micro
- An Overview of the New Rhysida Ransomware Trend Micro