{"id":453,"count":0,"description":"<div class=\"actor-dossier\" style=\"display:flex;flex-wrap:wrap;gap:12px;margin-bottom:20px\">\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Year Established<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">2023<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Attribution<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Unknown<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Motivation<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Financial<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Modus Operandi (MO)<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Double-extortion ransomware, healthcare targeting, VPN exploitation, auctioning victim data<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Primary Aliases<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Rhysida Ransomware Group<\/div>\n  <\/div>\n<\/div>\n<p>Rhysida is a ransomware group that emerged in mid-2023 and rapidly attracted attention for high-profile attacks against healthcare providers and government entities, as well as for an unconventional data monetisation approach that distinguishes them from typical ransomware operators. The group conducts double-extortion operations combining file encryption with data theft, but uniquely has experimented with auctioning stolen victim data to the highest bidder rather than simply threatening publication ,  creating a competitive bidding dynamic among potential buyers of sensitive information.<\/p>\n<p>Rhysida gained significant media attention through their attack on Insomniac Games (a PlayStation studio), from which they exfiltrated and published approximately 1.67 terabytes of internal data including unreleased game content, employee personal data, and internal business documents after the studio declined to pay ransom. The attack demonstrated Rhysida's willingness to follow through on data publication threats against cultural sector targets as effectively as against more traditional corporate victims.<\/p>\n<p>Healthcare organisations have been disproportionately targeted by Rhysida, including multiple hospital systems in the United States and internationally ,  attacks that CISA specifically warned about in a November 2023 advisory alongside the FBI. Their healthcare targeting prompted particular government concern given the direct patient safety implications of hospital system disruptions and the sensitivity of medical records as leverage for extortion.<\/p>\n<p>Rhysida's ransomware is built using the LibTomCrypt library and targets Windows environments, with researchers noting several technical similarities suggesting potential connections to the Vice Society ransomware group. The group recruits affiliates through underground forums and provides a negotiation platform and data leak infrastructure, operating with the organisational structure of an established RaaS operation despite their relatively recent emergence.<\/p>\n\n<p><strong>Threat Mitigation and Strategic Hardening:<\/strong> Network defense against campaigns linked to <strong>Rhysida<\/strong> requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our <a href=\"https:\/\/cyberasia.io\/cyber-risk-checker\/\" style=\"color: #facc15; text-decoration: none;\">Cyber Risk Checker<\/a> and report critical indicators via <a href=\"https:\/\/cyberasia.io\/secure-drop\/\" style=\"color: #facc15; text-decoration: none;\">Secure Drop<\/a>.<\/p>","link":"https:\/\/cyberasia.io\/actor\/rhysida\/","name":"Rhysida","slug":"rhysida","taxonomy":"threat_actor","parent":0,"meta":[],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors\/453","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/taxonomies\/threat_actor"}],"wp:post_type":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts?threat_actors=453"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}