rhysida

Ransomware
Sourceransomware.live

Vexday analysis

Rhysida é uma operação de ransomware-as-a-service (RaaS) que surgiu em maio de 2023, utilizando ataques de phishing e o Cobalt Strike para comprometer redes e implantar suas cargas maliciosas. O grupo ameaça divulgar publicamente os dados exfiltrados caso o resgate não seja pago, com as instruções de contato entregues por meio de notas em PDF deixadas nas pastas afetadas e pagamentos realizados em Bitcoin. Foram identificadas 5 vítimas do grupo no Brasil.

Exploited vulnerabilities 1

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Impact and victims

The group rhysida has 5 known ransomware victims. See the most affected sectors and countries and recent victims.

5known victims
5in Brazil
3sectors hit
Most attacked sectors
Education2
Manufacturing2
Healthcare1
Most affected countries
🇧🇷 Brasil5
Recent victims
Carrera ChevroletManufacturing · BR · 2025-05-26
TermolarManufacturing · BR · 2025-05-18
Sao Camilo Cachoeiro de ItapemirimEducation · BR · 2025-05-14
Unimed Vales do Taquari e Rio PardoHealthcare · BR · 2024-05-08
Federal University of Mato Grosso do SulEducation · BR · 2023-10-02

rhysida uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →