Skip to content

Hide Navigation Hide TOC

Rhysida Ransomware (f7c1e1cd-cc64-4417-92c3-76afed55d38c)

Rhysida is a ransomware-as-a-service (RaaS) operation that has been active since May 2023, claiming attacks on multiple sectors in several countries in North and South America, Western Europe, and Australia. Many alleged victims are education sector entities. Security researchers have observed TTP and victimology overlaps with the Vice Society extortion group.[HC3 Analyst Note Rhysida Ransomware August 2023]

Cluster A Galaxy A Cluster B Galaxy B Level
Rhysida Ransomware Actors (0610cd57-2511-467a-97e3-3c810384074f) Tidal Groups Rhysida Ransomware (f7c1e1cd-cc64-4417-92c3-76afed55d38c) Tidal Software 1