DataBreaches.net

DataBreaches.net

The Office of Inadequate Security

Menu
  • Breach Laws
  • About
  • Donate
  • Contact
  • Privacy
  • Transparency Reports
Menu

HC3: Sector Alert: Rhysida Ransomware

Posted on August 7, 2023August 7, 2023 by Dissent

August 4, 2023
TLP:CLEAR
Report: 202308041500

Executive Summary

Rhysida is a new ransomware-as-a-service (RaaS) group that has emerged since May 2023. The group drops an eponymous ransomware via phishing attacks and Cobalt Strike to breach targets’ networks and deploy their payloads. The group threatens to publicly distribute the exfiltrated data if the ransom is not paid. Rhysida is still in early stages of development, as indicated by the lack of advanced features and the program name Rhysida-0.1. The ransomware also leaves PDF notes on the affected folders, instructing the victims to contact the group via their portal and pay in Bitcoin. Its victims are distributed throughout several countries across Western Europe, North and South America, and Australia. They primarily attack education, government, manufacturing, and technology and managed service provider sectors; however, there has been recent attacks against the Healthcare and Public Health (HPH) sector.

Read the full report or download it at https://www.hhs.gov/sites/default/files/rhysida-ransomware-sector-alert-tlpclear.pdf

For related media coverage, see also Authorities Warn Health Sector of Attacks by Rhysida Group

Related Posts:

  • Rhysida ransomware group claims attack on Martinique
  • HC3: Sector Alert: Akira Ransomware
  • Emotet now drops Cobalt Strike, fast forwards…
  • Rhysida claims responsibility for attacks on two…
  • HC3: Analyst Note: 8Base Ransomware

Post navigation

← Jefferson County Health Center notifies patients about May cyberattack
Il: Cyberattack shuts down Bnei Brak hospital’s computers →

Sponsored or Paid Posts

This site doesn’t accept sponsored posts and doesn’t respond to requests about them.

Have a News Tip?

Email:

Breaches[at]Protonmail.ch
Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Telegram: @DissentDoe

Browse by News Section

Latest Posts

  • Why we need legislation requiring more transparency in breach notices, Saturday edition (Bluefield University)
  • The EU’s Cyber Resilience Act Has Now Been Agreed
  • 60 credit unions facing outages due to ransomware attack on popular tech provider
  • Paris Criminal Court Dismissed Charges Against Platypus Hackers
  • NYS Comptroller Audit: North Tonawanda City School District – Information Technology (2023M-102)
  • NYS Comptroller Audit: Brentwood Union Free School District – Information Technology (2023M-83)
  • If you’re in Rock County, Wisconsin, do NOT read this post. Absolutely do not read this post.
  • PA: Great Valley School District Falls Victim to Ransomware Attack

Please Donate

If you can, please donate XMR to our Monero wallet because the entities whose breaches we expose are definitely not supporting our work and are generally trying to chill our speech!

Donate- Scan QR Code   Donate!

Social Media

Find me on Infosec.Exchange.

I am also on Telegram @DissentDoe.

RSS

Grab the RSS Feed

Copyright

© 2009 – 2023, DataBreaches.net and DataBreaches LLC. All rights reserved.

HIGH PRAISE, INDEED!

“You translate “Nerd” into understandable “English” — Victor Gevers of GDI Foundation, talking about DataBreaches.net

©2023 DataBreaches.net