Home/Threat Actor/Rhysida
Threat Actor

Rhysida

rhysida_ransomware · russia_aligned_cybercrime · active since 2023

Rhysida (Vanilla Tempest / G1052) is one of the more operationally consequential newer ransomware operations of the 2023-2024 period , a financially-motivated organized cyber-criminal cluster operating predominantly from Russia and adjacent post-Soviet states emerging in May 2023, widely treated by modern vendor consensus as a Vice Society successor or personnel-overlap operation following Vice Society's apparent operational decline in mid-2023, with sustained healthcare-and-education-sector targeting emphasized in the CISA + FBI + MS-ISAC joint cybersecurity advisory AA23-319A (November 15, 2023)

most operationally consequential operations include the Chilean Army attack (May 2023, ~360K internal documents published, one of the most consequential ransomware attacks against a national military in the publicly-tracked record), Prospect Medical Holdings (August 2023, 16+ US hospitals across CA/CT/PA/RI with weeks of operational disruption), Kuwait Ministry of Finance (September-October 2023), the British Library attack (October 28, 2023 disrupting operations for months with the British Library refusing ~£600K ransom and Rhysida publishing ~600GB internal data, British Library's subsequent March 2024 detailed public incident-disclosure report representing an operationally significant transparency model for public-sector victim response), Insomniac Games / Sony PlayStation Studios (November-December 2023, ~1.6TB internal data published including unreleased Marvel's Wolverine game development assets), and Lurie Children's Hospital Chicago (January-February 2024 disrupting pediatric healthcare operations for weeks)

distinctive helpdesk-themed leak site branding.

initial-access tradecraft centers on spear- phishing + VPN credential stuffing against MFA-less endpoints + RDP credential theft + selective n-day exploitation.

cluster operates Linux + ESXi ransomware variants alongside Windows variant.

russia_aligned_cybercrime confidence: high 8 aliases

Profile

Rhysida (also tracked as Vanilla Tempest [Microsoft] and MITRE ATT&CK G1052) is one of the more operationally consequential newer ransomware operations of the 2023-2024 period, a financially-motivated organized cyber-criminal cluster operating predominantly from Russia and adjacent post-Soviet states emerging in May 2023. The cluster has substantial documented tooling-and-victimology overlap with the older Vice Society ransomware operation (active approximately 2021-2023) and modern vendor consensus widely treats Rhysida as a Vice Society successor or personnel-overlap operation following Vice Society's apparent operational decline in mid-2023. The cluster's most operationally distinctive cluster signature is sustained healthcare-and-education-sector targeting emphasized in the CISA + FBI + MS-ISAC joint cybersecurity advisory AA23-319A (November 15, 2023), the most operationally significant US-government formal public attribution for the cluster.

The healthcare-and-education-sector focus represents a meaningful operational-doctrine signal about cluster victim- selection patterns and aligns with broader Vice Society / Rhysida ecosystem operational patterns. The cluster's most operationally consequential operations include: First, the Chilean Army attack (May 2023), earliest high- profile Rhysida operation with subsequent publication of approximately 360,000 internal Chilean Army documents. One of the most operationally consequential ransomware attacks against a national military in the publicly-tracked record.

Second, Prospect Medical Holdings (August 2023), US healthcare network operating 16+ hospitals across California, Connecticut, Pennsylvania, and Rhode Island with weeks of operational disruption including emergency departments on paper-based clinical workflows. Third, the Kuwait Ministry of Finance (September-October 2023), Kuwait government financial-administration IT disruption. Fourth, and most operationally consequential UK incident, the British Library attack (October 28, 2023).

The cluster attacked the British Library disrupting operations for months including its main website, online catalogues, on-site IT systems, and Wi-Fi services. The British Library publicly refused the approximately 600,000 GBP ransom demand, and Rhysida subsequently published approximately 600GB of internal British Library data on the Rhysida leak site. The attack was operationally consequential beyond the British Library itself because of substantial cascading impact on UK academic research community (the British Library serves as major UK research- library infrastructure).

The British Library subsequently published an unusually detailed public incident-disclosure report (March 2024) documenting full attack details, an operationally significant transparency model for public-sector victim response. Fifth, Insomniac Games / Sony PlayStation Studios (November- December 2023), high-profile entertainment-industry operation against the Sony Interactive Entertainment subsidiary video-game development studio. Approximately 1.6 terabytes of Insomniac Games internal data published on the Rhysida leak site including unreleased game development materials (notably extensive Marvel's Wolverine game development assets that had not been publicly disclosed by Sony), employee personal information, contracts, and financial information.

Sixth, Lurie Children's Hospital Chicago (January-February 2024), pediatric healthcare operations disrupted for weeks including delayed surgeries and rerouted patients. The cluster operates a distinctive helpdesk-themed leak site featuring customer-service-style branding, operationally novel relative to peer ransomware leak sites and contributing to elevated public-recognition profile. The branding choice is consistent with broader contemporary ransomware-cluster pattern of distinctive leak-site aesthetic (Akira's retro 1988 green- text styling, ALPHV / BlackCat's Tor-based clear-web-indexing, Medusa's ransom-countdown timers, collectively representing cluster-level investment in public-facing branding as marketing dimension).

Operationally the cluster's initial-access tradecraft centers on spear-phishing with weaponized attachments, VPN credential stuffing against MFA-less VPN authentication endpoints, RDP credential theft from underground marketplaces and infostealer deployments, and selective exploitation of disclosed n-day vulnerabilities. The cluster operates Linux + ESXi ransomware variants alongside the Windows variant. A handful of operational notes: First, the cluster's Vice Society successor relationship is one of the better-documented examples of ransomware-cluster-personnel- reorganization-under-new-brand in the publicly-tracked record.

Vice Society (active approximately 2021-2023) was documented under CISA + FBI + MS-ISAC + UK NCSC AA22-249A advisory (September 6, 2022) for sustained education-sector targeting; the Rhysida successor brand has continued the sector-targeting focus while operating substantially-modified tooling and operational branding. Second, the British Library's March 2024 public incident- disclosure report represents an operationally significant transparency model for public-sector victim response. The detailed disclosure, including the cluster's initial-access vector, the operational impact assessment, the recovery costs, and the decision-making process around ransom refusal, provides defender and policy-maker reference material that contrasts with the conventional silent-incident-response approach.

The British Library model contributes to broader analytical questions about whether systematic public-disclosure patterns could undermine ransomware operational viability over time. Third, no formal individual-operator attribution at the named- Russian-national tier has been publicly issued for Rhysida administrators, consistent with the broader pattern of absence of similar named-individual-attribution for Cl0p, ALPHV / BlackCat, Black Basta, Akira, Play, Medusa, and several other contemporary cybercrime clusters. Only LockBit (Khoroshev), Evil Corp (Yakubets / Turashev), and FIN7 (Dunaev / Hladyr / Kolpakov / Witte) have received named-Russian-national-tier formal attribution among the major contemporary cybercrime clusters covered in this corpus.

Fourth, the healthcare-and-education-sector targeting pattern represents operationally significant defender threat-modeling guidance. Healthcare and education sector organizations consistently face under-resourced cybersecurity programs relative to other comparable verticals, making them disproportionately attractive victim categories for ransomware operations like Rhysida and Vice Society predecessor. Defender threat-modeling for these sectors should treat ransomware as primary threat category requiring substantial resource allocation comparable to other comparable verticals.

Aliases

8
rhysidarhysida ransomwarerhysida_ransomwarerhysidaransomwarerhysida gangrhysida_gangatk 277atk277

Notable Campaigns

9
2024-2025Continued Operations (2024-2025)
2023-2024Sustained US State and Local Government Targeting (2023-2024)
2023Rhysida Emergence (May 2023)
2023Chilean Army Attack (May 2023)
2023Kuwait Ministry of Finance Attack (September-October 2023)
2023Prospect Medical Holdings Attack (August 2023)
2023CISA + FBI + MS-ISAC AA23-319A Rhysida Cybersecurity Advisory (November 15, 2023)
2023British Library Attack (October 28, 2023)
2023Insomniac Games / Sony PlayStation Studios Attack (December 2023)

Attribution & Reporting

Attributed by
FBI Cyber DivisionCISA (US Cybersecurity and Infrastructure Security Agency)HHS Health Sector Cybersecurity Coordination Center (HC3)Multi-State Information Sharing and Analysis Center (MS-ISAC)UK National Cyber Security Centre (NCSC)Mandiant / Google Cloud Threat IntelligenceMicrosoft Threat Intelligence CenterCrowdStrikeRecorded Future Insikt GroupSentinelOneSophosTrend MicroKaspersky GReATGroup-IBPRODAFTCovewareHalcyonCybereasonIBM X-ForceTrustwave SpiderLabsPalo Alto Networks Unit 42Symantec (Broadcom)TrellixDFIR ReportBitdefenderGuidePoint Security
Key reporting
reportCISA + FBI + MS-ISAC: AA23-319A #StopRansomware Rhysida Ransomware Joint Cybersecurity Advisory (November 15, 2023), most operationally significant US-government formal public attribution
reportBritish Library: Learning Lessons from the Cyber-Attack (March 2024), operationally significant transparency model for public-sector victim response with full incident disclosure
reportCrowdStrike: Rhysida Ransomware and Vice Society Overlap Tracking
reportMandiant: Rhysida Ransomware Continued Tracking
reportCisco Talos: Rhysida Ransomware Deep Dive
reportPalo Alto Networks Unit 42: Rhysida Ransomware Operational Analysis
reportBitdefender: Rhysida Ransomware Tracking
reportTrend Micro: Rhysida Ransomware Spotlight (August 2023)
reportSentinelOne Labs: Rhysida Ransomware The Detection Side
reportMicrosoft Threat Intelligence: Vanilla Tempest / Rhysida (January 2024)
reportRecorded Future Insikt Group: Rhysida Ransomware Emerging Tracking
reportSophos: Rhysida Ransomware Vice Society Overlap (August 2023)
reportCoveware: Rhysida Ransomware Affiliate Tracking
reportHalcyon: Rhysida Operational Profile
reportPRODAFT: Rhysida Detailed Operational Analysis
reportGroup-IB: Rhysida Continued Tracking
reportTrustwave SpiderLabs: Rhysida Tracking
reportTrellix: Rhysida Operational Analysis
reportSymantec (Broadcom): Rhysida Ransomware Tracking
reportDFIR Report: Rhysida Operational Analysis
reportGuidePoint Security: Rhysida Incident Response Tracking
reportMalpedia Actor Profile: Rhysida
reportMITRE ATT&CK Group G1052, Rhysida

Operational

State sponsor

Rhysida is a financially-motivated organized cyber-criminal cluster, not a state-aligned cluster, operating predominantly from Russia and adjacent post-Soviet states. The cluster emerged in May 2023 and represents one of the more operationally consequential newer ransomware operations of the 2023-2024 period. The cluster has substantial documented tooling-and- victimology overlap with the older Vice Society ransomware operation (active approximately 2021-2023), and modern vendor consensus widely treats Rhysida as a Vice Society successor or personnel-overlap operation following Vice Society's apparent operational decline in mid-2023.

Microsoft Threat Intelligence Center has tracked the cluster under the Vanilla Tempest naming and documented apparent personnel-and-tooling overlap with both Vice Society and additional ransomware affiliate operations. The cluster has received the most operationally significant US- government formal public attribution among 2023-emerging ransomware operations through CISA + FBI + MS-ISAC joint cybersecurity advisory AA23-319A (November 15, 2023) documenting Rhysida tradecraft and indicators of compromise specifically focused on healthcare-and-education sector targeting. No formal individual-operator attribution at the named-Russian-national tier has been publicly issued for Rhysida administrators.

Motivations
financial_gain, financially_motivated, cybercrime, ransomware_deployment, extortion, double_extortion, data_theft_for_extortion, ransomware_as_a_service_operations, healthcare_sector_targeting, education_sector_targeting
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)29/60 · 48%
Runtime / container (Falco)8/60 · 13%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

2 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MEGA NZMETERPRETERMSHTASHARPHOUNDSPLASHTOP ABUSESYSMON ABUSE
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin