Ransomware group profile · #25 by claimed victims
Rhysida ransomware
Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks and Cobalt Strike to breach the targets' networks and deploy their payloads.<br> <br> The group threatens to publicly distribute exfiltrated data if the ransom is not paid, and it's worth mentioning that Rhysida is still in the early stages of development.<br> <br> The ransomware leaves PDF notes in the affected folders, instructing victims to contact the group through its portal, and payment is made via Bitcoin.<br> <br> After encryption, the ransomware appends the extension '.ryshida' to encrypted files.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs
Victimology
Who Rhysida claims to have breached, from 291 leak-site posts recorded by VULONE.
Claims per month last 12 months
Top sectors
Top countries
Latest claimed victims 12 most recent
| Victim | Sector | Country | Claimed |
|---|---|---|---|
| Axdia International | — | — | 12 Sep 2026 |
| Axdia International axdia.com | Professional Services | — | 12 Sep 2026 |
| General Santos Doctors Hospital | — | — | 10 Sep 2026 |
| Professional Retail Services | — | — | 10 Sep 2026 |
| General Santos Doctors Hospital | Healthcare | PH | 10 Sep 2026 |
| Professional Retail Services | Retail & E-Commerce | — | 10 Sep 2026 |
| SAD'S Interim | — | — | 8 Sep 2026 |
| SAD'S Interim sads-interim.eu | Professional Services | FR | 8 Sep 2026 |
| Rug & Home | Retail & E-Commerce | US | 7 Sep 2026 |
| Szechenyi Programiroda Nonprofit Kf | Other | HU | 1 Sep 2026 |
| Valley Health Team | Healthcare | — | 28 Aug 2026 |
| Berlin, Germany | Not Found | DE | 28 Aug 2026 |
All 291 Rhysida victims, searchable
Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.
Tactics, techniques and procedures
ATT&CK technique mapping for Rhysida is in progress. Victimology, infrastructure status and leak-site tracking are live above.
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Frequently asked
Is Rhysida ransomware still active?
How many victims has Rhysida claimed?
Which industries does Rhysida target?
Which countries are most affected by Rhysida?
Where does VULONE get Rhysida victim data?
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].