◇ SIGN IN
← all actors
ransomware

Rhysida

activemedium confidence
Ransomware
RhysidaVice Society-linked (assessed)
Attribution
RaaS (financially motivated, unattributed)
Origin
Unknown
First seen
2023
Last active
2026
Motivation
Financially motivated (ransomware)
Confidence
medium
MENA targeting
Kuwait, UAE
Sectors
Government, finance, health ministry, technology

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting Kuwait, UAE (Government, finance, health ministry sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Rhysida is a ransomware-as-a-service operation active since May 2023 that hits targets of opportunity across education, healthcare, manufacturing, IT and government, using double extortion.

History

Rhysida emerged in May 2023 and operates a RaaS model, deploying against targets of opportunity in education, healthcare, manufacturing, information technology and government. It steals data first and encrypts later, then threatens publication on its leak/'auction' site if the victim does not pay. A joint CISA/FBI/MS-ISAC advisory (AA23-319A) documents its tradecraft, and open-source reporting notes overlaps with Vice Society (DEV-0832) activity.

The operation remained highly active through 2025-2026. CISA updated the Rhysida advisory in April 2025 with fresh indicators and added Gootloader as a confirmed initial-access vector. In October 2025, Microsoft disrupted a Vanilla Tempest campaign that used fake Microsoft Teams installers and the Oyster backdoor to deploy Rhysida, revoking more than 200 fraudulently used code-signing certificates.

Rhysida's leak site has listed victims in Kuwait and the UAE among its international claims. Such listings are the group's own extortion allegations and should be treated as claims, not confirmed breaches, unless independently verified.

Notable campaigns

2023
Public-sector / healthcare campaign
CISA/FBI/MS-ISAC advisory documented Rhysida attacks across education, healthcare and government.
2025
CISA advisory update (Gootloader)
April 2025 update added Gootloader as a confirmed initial-access vector and refreshed indicators.
2025
Vanilla Tempest fake-Teams deliveries
Microsoft disrupted a campaign using fake Teams installers and the Oyster backdoor to deploy Rhysida.

Claimed victims · 273 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

Claim volume · last 12 months
SONDJFMAMJJA
DateVictimCountrySector
Lawson RoofingManufacturing
IDS GroupUSProfessional Services
Landeshauptstadt StuttgartDEGovernment & Defense
Tower View Primary SchoolGBEducation
Stelia North AmericaUSManufacturing
Southold Town Senior ServicesSouthold Police DepartmentGovernment & Defense
RohnerCHManufacturing
Leading Edge SpecialiProfessional Services
Lakeside Union School DistrictUSEducation
ElabsSETechnology
Jet-care InternationalCHTransportation
Charles Leonard Steel ServicesUSManufacturing