Cyber Threat Report: 'StopRansomware: Rhysida Ransomware'

Report Author CISA
Publication Date 2023-11-15
Original Reporting Source
Related Intrusion Sets Rhysida Ransomware Gang
Identified CVEs CVE-2020-1472
Victim Sectors Public Services, Education, Healthcare, Manufacturing, Technology

This is a joint Cybersecurity Advisory by the Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC). The advisory outlines indicators of compromise (IoCs) and tactics, techniques and procedures (TTPs) associated with Rhysida ransomware attacks. The report states that threat actors have deployed Rhysida ransomware against targets of opportunity across multiple sectors including education, healthcare, manufacturing, information technology, and government. It notes open source reporting on similarities with Vice Society/DEV-0832. In terms of operating model, the advisory notes that researchers have Rhysida using the ransomware-as-a-service (RaaS) approach, with ransomware tools and infrastructure leased to affiliates in a profit-sharing model - ransom money is then divided between the Rhysida operators and the affiliates.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques