All threat actors

Rhysida

Alert me

A ransomware-as-a-service and double-extortion operation active since 2023. Its affiliates target education, healthcare, government, manufacturing, and other sectors using phishing, valid credentials, exposed services, and commodity tools before stealing data and encrypting Windows systems.

Create a free account to see the reports

Sign in or create a free account to see every report that names Rhysida.

Create free account