Rhysida Ransomware Group: Dark Web Data Leak Case Study
- securedmonk
- Jun 29
- 14 min read

Executive Summary
The emergence of the Rhysida Ransomware Group in May 2023 signaled a rapid, aggressive shift in the threat landscape, challenging established paradigms of corporate defense. Posing as a benign "cybersecurity team" performing simulated penetration audits, this highly active Cybercrime Group uses specialized payloads to encrypt files and exfiltrate sensitive directories. Rhysida's operations are defined by their uncompromising posture: they target high-value enterprise entities across sectors where operational downtime is intolerable, such as healthcare, education, manufacturing, and government. This Rhysida Case Study analyzes the technical mechanics, dark web operational infrastructure, and victimology of Rhysida, demonstrating how they utilize a dual-pronged approach to maximize extortion leverage.
By combining tactical network intrusions with a sophisticated public Data Leak Site, the group forces victims into a compressed timeline for negotiations. Unlike traditional groups that use data leak sites merely as repository archives, Rhysida operates an interactive, auction-based Rhysida Dark Web Portal to sell stolen corporate assets directly to the highest bidder. This analysis outlines the entire attack sequence, examines the underlying cryptographic vulnerabilities that led to the partial cracking of their Windows payload, and provides structured mitigation strategies to secure modern enterprise networks against this persistent threat.

Rhysida Ransomware Group at a Glance (Quick Threat Profile)
To understand Rhysida's positioning within the broader cybercrime ecosystem, a detailed Threat Actor Profile must be established to trace their access vectors, monetization strategies, and core targeting patterns. The table below provides a structured overview of the group's operational parameters:
Attribute | Details |
First Detected | May 2023 (Infrastructure prepared as early as March 2023) |
Threat Actor Type | Ransomware-as-a-Service (RaaS) operator and extortionist collective |
Primary Monetization | Double Extortion Ransomware (Data encryption + public auctions) |
Initial Intrusion Vectors | Phishing, compromised VPN credentials, and remote execution vulnerabilities |
Key Targets | Healthcare, Academic/Education, Heavy Manufacturing, and Public Services |
Exfiltration Strategy | Manual staging using specialized backdoors and cloud exfiltration tools |
Cryptographic Standard | ChaCha20 stream cipher wrapped in RSA-4096-OAEP key distribution |
Primary Payment Method | Bitcoin (BTC) via customized dark web portals |
What makes the Rhysida Ransomware Group different from traditional ransomware groups is their fluid operational model and total lack of ethical boundaries. While legacy syndicates occasionally avoid critical public services like hospitals or schools to bypass aggressive law enforcement pressure, Rhysida purposefully targets these vulnerable networks to exploit their low downtime tolerance. Furthermore, their close relationship with other active threat clusters most notably their documented alignment with actors previously associated with Vice Society allows them to quickly adopt refined tools, specialized initial access brokers, and highly effective lateral movement playbooks.
Understanding Rhysida's Dark Web Leak Site
The core of Rhysida's extortion strategy is the Rhysida Leak Site, a highly structured platform hosted on the Tor network. Unlike simple repositories that list static links to stolen directories, the Rhysida Onion Site is designed to mimic a professional, interactive auction house. This interface is optimized to generate intense public and regulatory pressure, accelerating the victim's timeline for payment.
Homepage Architecture
The homepage of the Rhysida Dark Web Portal features a clean, minimalist layout dominated by the group's signature centipede logo. At the top of the interface, dynamic counters display the number of active, real-time auctions alongside a total count of victims processed by the platform. A prominent input field labeled "Token" allows victims to input the unique cryptographic identifier provided in their ransom note, immediately redirecting them to a private, secure communication portal. This homepage acts as the primary public interface, exposing targeted organizations to the world.
Stolen Data Archive
For victims who refuse to negotiate, the portal maintains a public archive containing fully exfiltrated datasets. Each listing in this archive includes the targeted company's logo, a brief description of their business operations, the total volume of exfiltrated data in gigabytes, and the exact count of files included in the dump. Progress bars are displayed on these listings, showing the percentage of the data that has been uploaded to public servers. Once the upload reaches 100%, the page provides direct links to multi-part, compressed archives hosted on decentralized storage services, making the data accessible to anyone.

Live Data Auctions
The defining feature of the site's extortion design is the Rhysida Auction interface. When a new victim is posted to the active Rhysida Victim List, the group initiates a formal countdown timer, usually set to seven days. During this period, the exclusive rights to purchase the stolen data are put up for bidding in a Rhysida Data Auction.

The layout displays the starting price denominated in Bitcoin (BTC), the exact time remaining on the clock, and a structured data preview. To maintain high-intensity pressure, the interface includes a comment section where external actors, initial access brokers, and potential buyers can communicate. Rhysida enforces a strict "no reselling" policy, declaring that the highest bidder will be the sole owner of the data, which encourages competition among threat actors and corporate competitors.
Technical Document Previews
To prove the authenticity of their data theft, Rhysida provides high-resolution document previews directly within each auction listing. These previews showcase sensitive internal documents, including architectural blueprints, employee identification cards, legal contracts, and financial audits. By displaying proof of access openly, Rhysida bypasses standard deniability strategies, forcing the victim's executive team to confront the reality of the breach.
Victim Contact and Support Panel
The platform includes an interactive communication panel protected by a custom graphical Captcha system designed to block automated bots and DDoS scraping tools. This portal allows victims to submit comments, exchange files, and negotiate ransom terms directly with Rhysida's support operators. The system also includes direct links to commercial cryptocurrency exchanges, complete with tutorials on how to acquire and transfer Bitcoin, lowering the technical barrier for payment.

Attack Lifecycle: How Rhysida Operates
The typical execution flow of a Rhysida Ransomware Attack is a fast, highly organized sequence designed to achieve complete domain compromise before security teams can react. This lifecycle moves systematically through the following phases:
Initial Access
Rhysida avoids highly complex zero-day exploitation for initial entry, relying instead on high-probability, proven entry points. The group frequently utilizes targeted phishing campaigns containing malicious attachments or links designed to harvest user credentials. Additionally, they leverage an Initial Access Broker to purchase legitimate but compromised credentials for external remote services. These are frequently used to log into corporate Virtual Private Network (VPN) devices that lack multi-factor authentication (MFA). In some instances, the group exploits unpatched, public-facing vulnerabilities in security appliances or utilizes sophisticated malvertising campaigns to deliver custom loader payloads.
Payload Delivery & CleanUpLoader Deployment
To establish a resilient beachhead within the target network, Rhysida operators deploy CleanUpLoader (also known as Oyster or Broomstick). Commonly disguised as legitimate utility setups like Microsoft Teams or Google Chrome installers, this C++ based backdoor is frequently signed with fraudulent digital certificates to bypass endpoint detection and response (EDR) agents. Once executed, the backdoor establishes persistence by creating periodic scheduled tasks and communicates with multi-tiered Command and Control (C2) servers via HTTPS, allowing the attackers to download secondary toolsets and run administrative commands.
Privilege Escalation & Reconnaissance
With a backdoor established, the threat actors execute tools to map the target domain and elevate their privileges. They often exploit known administrative configuration flaws or vulnerabilities like Zerologon (CVE-2020-1472) to quickly gain domain administrator rights. Internal reconnaissance is conducted using lightweight utilities, such as Advanced Port Scanner and customized PowerShell scripts, allowing the attackers to map the network architecture and locate high-value assets like Active Directory databases, critical servers, and storage repositories.
Credential Theft & Lateral Movement
Rhysida actively targets authentication material to secure their control over the network. They use utilities to dump the memory of the Local Security Authority Subsystem Service (lsass.exe) to harvest plaintext credentials and Active Directory hashes. In many cases, they target Active Directory domain controllers, utilizing the native ntdsutil.exe utility to extract and dump the entire Active Directory database file (ntds.dit), capturing credential hashes for every user in the organization. Lateral movement is then executed using administrative channels, such as Remote Desktop Protocol (RDP), PsExec, and Windows Remote Management (WinRM).
Staging, Exfiltration, & Encryption Execution
Before launching the encryption routine, Rhysida operators stage and exfiltrate sensitive files. They create dedicated directories on compromised hosts, manually appraise and gather files containing personally identifiable information (PII) and intellectual property, and compress the datasets into multi-part archives.
Exfiltration is conducted using tools like Azure Storage Explorer or rclone to upload the data to attacker-controlled cloud storage accounts. Once exfiltration is verified, the threat actors deploy the ransomware payload across all accessible endpoints and hypervisors, encrypting files, dropping ransom notes, and initiating the dark web publication sequence.
Technical Analysis of Rhysida
A deep Rhysida Ransomware Analysis reveals a payload engineered for high-speed encryption across both enterprise workstations and virtualized hypervisor environments.
Compilation and Tooling Details
The primary Windows payload is compiled as a 32-bit or 64-bit Portable Executable (PE) using MinGW and the GNU Compiler Collection (GCC). For its cryptographic functions, the malware developers avoided writing custom encryption routines, choosing instead to integrate the open-source LibTomCrypt library. This design allows the payload to perform highly optimized, parallelized file locking by spawning threads equivalent to the total number of logical processors on the target system.
Encryption Mechanics
To achieve maximum speed, Rhysida uses a hybrid encryption scheme. The file content is encrypted using the ChaCha20 stream cipher. The unique 32-byte key and 12-byte initialization vector (IV) generated for each file are then encrypted using an embedded, hardcoded RSA-4096 public key with Optimal Asymmetric Encryption Padding (OAEP). This encrypted 512-byte key envelope is appended to the tail of the encrypted file along with a footer containing a file marker.
Furthermore, the payload uses intermittent encryption. For files larger than 1 megabyte (MB), the locker breaks the file into several blocks and only encrypts 1 MB of data within each block, leaving the remaining data unencrypted. This technique corrupts the file header and structure, making it unreadable while drastically reducing the time required to complete the attack.
The Key-Generation Vulnerability and KISA's Decryptor
In early 2024, researchers from Kookmin University and the Korea Internet & Security Agency (KISA) identified a significant implementation flaw in Rhysida's key-generation process. While the developers used LibTomCrypt's secure pseudo-random number generator (PRNG), they initialized the generator's seed using a highly predictable variable: the current system time.
Because the main execution thread compiles a sequential list of files to be encrypted and passes them to parallel sub-threads, the timestamp changes between file executions were highly predictable. This design error allowed researchers to drastically narrow the range of potential seed keys. By tracking the file write sequence on an infected system, the KISA tool can reconstruct the PRNG's state, regenerate the encryption keys, and decrypt the files without paying a ransom.
However, this vulnerability applies strictly to the Windows PE locker. It does not affect the group's Linux, ESXi, or PowerShell-based variants, meaning organizations using virtualized hypervisors cannot rely on this decryption tool.
Evasion and Living-off-the-Land Tactics
Rhysida relies on PowerShell scripts, most notably a script known as SILENTKILL. This script is executed prior to deploying the ransomware payload and is designed to identify and terminate local security software, modify the local firewall rules, clear the Windows event logs, change Active Directory administrative passwords to lock out defenders, and delete local system backups and volume shadow copies using vssadmin.exe. Additionally, some versions of the payload include self-deletion commands to remove the ransomware binary immediately after execution, complicating post-incident forensics.
Command Line Arguments and Features
The Rhysida Windows executable supports several execution parameters, allowing operators to customize the payload's behavior:
-d <path> Specifies a target directory to encrypt. If omitted, the locker traverses all local drives. [cite: 33]-sr Enables self-deletion of the ransomware binary immediately after the encryption run is completed. [cite: 33]-nobg Disables the modification of the host wallpaper to the ransom notification. [cite: 33]-S Creates a persistent scheduled task named "Rhsd" to run the payload under SYSTEM context.-md5 Pre-calculates the MD5 file hash prior to encryption (an incomplete utility function). [cite: 33]MITRE ATT&CK Mapping
The operational behavior of Rhysida throughout an intrusion is mapped to the MITRE ATT&CK framework below:
Tactic | Technique Name | ID | Description / Implementation Details |
Initial Access | Phishing: Malicious Link / Attachment | T1566 | Delivers malicious email attachments and payload links. |
Initial Access | Valid Accounts: External Services | T1078 | Authenticates to corporate VPN networks using compromised credentials. |
Execution | Command and Scripting Interpreter | T1059.001 | Runs PowerShell scripts (SILENTKILL) to terminate services and clear event logs. |
Persistence | Scheduled Task/Job: Scheduled Task | T1053.005 | Creates persistent tasks named "Rhsd" via command arguments or CleanUpLoader routines. |
Privilege Escalation | Exploitation of Remote Services | T1210 | Exploits Netlogon vulnerabilities (Zerologon) to gain domain administration. |
Defense Evasion | Impair Defenses: Disable Tools | T1562.001 | Disables security applications and modifies Active Directory settings. |
Defense Evasion | Indicator Removal: File Deletion | T1070.004 | Executes PowerShell self-deletion scripts to clean up files after execution. |
Credential Access | OS Credential Dumping: LSASS | T1003.001 | Uses memory dump utilities like ProcDump on lsass.exe. |
Discovery | System Network Connections Discovery | T1049 | Runs port scanners and native network commands to identify host machines. |
Lateral Movement | Remote Services: Remote Desktop Protocol | T1021.001 | Moves laterally between targets using compromised administrative credentials. |
Exfiltration | Transfer Data to Cloud Storage | T1567.002 | Uses Azure Storage Explorer to upload stolen datasets to cloud storage. |
Impact | Data Encrypted for Impact | T1486 | Encrypts files using ChaCha20 and appends the .rhysida extension. |
Victim Analysis & Industry Trends
A detailed Ransomware Group Analysis demonstrates that Rhysida's targeting strategy is highly opportunistic, focusing on sectors that face high public pressure and regulatory compliance burdens. By targeting these environments, they exploit the high recovery costs and low downtime tolerance of their victims, increasing the likelihood of a payout.
Sector Distribution
The group's victimology focuses heavily on four primary sectors:
Healthcare and Public Health (HPH): Rhysida targets hospitals, diagnostic networks, and urgent care clinics, recognizing that systems disruption directly threatens patient safety. Notable attacks include Prospect Medical Holdings and Lurie Children's Hospital.
Education and Academic Services: The group frequently targets public school systems and universities, exploiting their limited security budgets and highly distributed network architectures.
Government and Public Infrastructure: Attacks on administrative entities, such as the City of Columbus and the Chilean Army, demonstrate the group's willingness to target sovereign government infrastructure.
Heavy Manufacturing & Construction: Industrial targets are selected due to their highly integrated supply chains, where a localized system outage can stall production lines and cause significant financial loss.
Geographical Target Patterns
Rhysida's attacks are global, targeting organizations across Europe, North America, and South America. The primary geographic concentrations of verified victims are listed in the table below:
Country Location | Relative Target Weight | Key Vulnerability Characteristics |
United States | High (~46% of cases) | Highly reliant on interconnected clinical platforms and vulnerable remote access portals. |
United Kingdom | Moderate | Focused on centralized public sector entities and academic institutions. |
Germany | Moderate | Heavy targeting of mid-market manufacturing hubs and local public administrations. |
Chile / Spain | Moderate | Vulnerable external access points and unpatched remote gateways. |
Dark Web Intelligence: What Businesses Can Learn from Leak Sites
For modern security teams, the Rhysida Leak Site is more than just an extortion portal; it is a critical source of Cyber Threat Intelligence. By systematically monitoring the activities on these portals, defenders can extract valuable indicators of compromise and contextual threat data.
Analyzing Stolen Data Assets
When data is uploaded to a Data Leak Site, threat intelligence analysts can evaluate the specific categories of files released during an auction. The typical classifications of leaked assets found on the portal include:
Corporate Identity Records: Passport copies, driver's licenses, and HR records. These files provide attackers with material for targeted social engineering campaigns.
Internal Network Blueprints: Network architecture maps, Active Directory structures, and asset inventories. These files can be sold to initial access brokers to facilitate follow-on compromises.
Financial and Legal Documentation: Proprietary contracts, quarterly tax filings, and insurance policies. This information is highly valuable to industrial competitors.
Early Exfiltration Indicators
Network intelligence research has demonstrated that defenders can track the infrastructure associated with Rhysida long before files are encrypted. By analyzing the multi-tiered C2 domains and payload delivery servers used by CleanUpLoader, security teams can detect ongoing intrusions during the attacker's dwell time.
In multiple cases, network traffic tracking identified victim exfiltration events an average of 30 days before the target's name appeared on the public Rhysida Victim List. This highlights the critical importance of monitoring early indicators of compromise (IOCs) rather than relying solely on file signature detection.
Business Impact Beyond Encryption
The consequences of a Rhysida Ransomware Attack extend far beyond the immediate technical cost of file decryption. When an enterprise is compromised, the downstream operational, financial, and reputational damages can persist for years.
Operational Disruptions
When critical infrastructure is encrypted, organizations are often forced to revert to manual processes. In healthcare environments, hospitals must shut down clinical systems, postpone surgeries, redirect emergency vehicles, and manage patient records on paper. In manufacturing, production lines halt, leading to contractual penalties, supply chain blockages, and lost market position.
Regulatory Fines and Compliance Exposures
Exfiltrating sensitive data triggers strict regulatory reporting requirements. Under frameworks like HIPAA or GDPR, organizations face severe financial penalties for failing to secure personally identifiable information (PII) and protected health information (PHI). Compromised organizations also face significant legal risks, including long-tail class-action lawsuits and regulatory audits that drain capital and resources.
Brand Damage and Trust Erosion
When customer and client data is publicly auctioned on a dark web portal, brand reputation is severely damaged. The exposure of proprietary designs, corporate correspondence, and employee records erodes stakeholder trust. This loss of confidence can lead to customer churn, decreased enterprise valuation, and increased difficulty in securing future business partnerships.
Detection & Defense Strategies
Organizations must implement a multi-layered security framework designed to prevent initial access, limit lateral movement, and quickly isolate compromise indicators.
Strategic Prevention Measures
To effectively mitigate the risk of initial compromise, the following baseline controls should be implemented:
Enforce Strict Identity Protections: Deploy phishing-resistant Multi-Factor Authentication (MFA) across all remote access vectors, particularly VPN devices, email portals, and administrative access points.
Vulnerability and Patch Management: Maintain a rigorous patching cadence for all public-facing services, particularly VPN appliances and remote management gateways.
Application Control and Access Whitelisting: Define strict application policies to prevent the execution of dual-use utilities, such as unauthorized remote monitoring and management (RMM) tools.
Strict Network Segmentation: Separate critical operations databases and internal active directory structures from standard corporate workstations to limit lateral movement.
Key Detection Signals
Security Operations Centers (SOC) should configure their monitoring tools to alert on the following threat behaviors:
Unusual Process Access: Alert on unauthorized attempts by non-system processes to access the memory of lsass.exe to create memory dumps.
Suspicious Active Directory Activity: Monitor execution patterns of administrative tools like ntdsutil.exe when utilized to export directory data.
Abuse of Administrative Tools: Track command execution patterns involving PsExec, RDP connections using administrative credentials, and anomalous PowerShell scripts.
Anomalous Cloud Traffic Outflows: Monitor massive, unauthorized data transfers to cloud platforms, particularly when utilizing utilities like rclone or Azure Storage Explorer.
Indicators of Compromise (IOCs)
Defenders should screen their environments for the following verified indicators of compromise associated with Rhysida operations:
Known Executable Hashes (SHA-256)
The following hashes represent known malicious binaries associated with Rhysida ransomware payloads, CleanUpLoader, and SILENTKILL PowerShell scripts:
Indicator Type | Cryptographic Hash (SHA-256) | Associated Malware / Tool Profile |
File Hash | f0668ce925f36ff7f3359b0ea47e3fa243af13cd6ad9661dfccc9ff79fb4f1cc | CleanUpLoader Backdoor Executable |
File Hash | 11af4566539ad3224e968194c7a9ad7b596460d8f6e423fc62d1ea5fc0724326 | CleanUpLoader Execution Payload |
File Hash | f0a6b89ec7eee83274cd484cea526b970a3ef28038799b0a5774bb33c5793b55 | Installer Dropper Payload |
File Hash | 97766464d0f2f91b82b557ac656ab82e15cae7896b1d8c98632ca53c15cf06c4 | Staging batch script (S_1.bat) |
File Hash | 918784e25bd24192ce4e999538be96898558660659e3c624a5f27857784cd7e1 | Execution script for conhost.exe (S_2.bat) |
File Hash | e5d4a2e704ee880273aa4e8114fe9927b0019ff8 | Rhysida Ransomware Encryptor Payload (conhost.exe) |
File Hash | 4e34b9442f825a16d7f6557193426ae7a18899ed46d3b896f6e4357367276183 | File Extension Blocklist Script (1.ps1) |
File Hash | a864282fea5a536510ae86c77ce46f7827687783628e4f2ceb5bf2c41b8cd3c6 | Rhysida Windows Locker Binary |
Operational Network and Host Indicators
The following domains, IPs, and system markers are associated with Rhysida C2 infrastructure and deployment scripts:
Indicator Type | Specific Target Value | Detailed Threat Context |
IP Address | Exfiltration Destination / Transport Host | |
IP Address | Known Command & Control Target Node | |
IP Address | Attacker Infrastructure Gateway | |
Domain | CleanUpLoader Initial Payload Delivery Site | |
Domain | Typosquatted Team impersonation URL | |
Domain | Impersonated PuTTY Landing Domain for Loader Delivery | |
File Name | CriticalBreachDetected.pdf | Hardcoded ransom note dropped in encrypted directories |
File Extension | .rhysida | Appended to encrypted files |
Key Lessons for Security Leaders
Analyzing the operations of the Rhysida Ransomware Group highlights several critical lessons for enterprise security leadership:
Backups Alone Are Not Enough: Legacy disaster recovery strategies that rely solely on system restoration fail to address the risk of data exfiltration. When a double-extortion actor captures sensitive files, the threat of public exposure remains a powerful lever even if system operations can be restored.
Early Exfiltration Detection Is Key: Real security resilience requires detecting attacks during the initial intrusion and staging phases, well before system encryption begins.
Identity Is the New Perimeter: Legitimate credentials stolen by initial access brokers bypass traditional perimeter security controls. Strengthening access controls, monitoring authentication anomalies, and enforcing least-privilege access are essential to securing the enterprise.
Conclusion
The Rhysida Ransomware Group continues to be a highly disruptive force in the cyber threat landscape, using refined double-extortion strategies to target critical infrastructure worldwide. By combining specialized loaders with an interactive public auction site, the group generates intense pressure to force quick payment decisions. While vulnerabilities in their payload's key-generation process have allowed defenders to develop decryption tools, these tools do not protect virtualized hypervisor environments or prevent the exposure of exfiltrated data.
To defend against this threat, enterprises must move beyond reactive security measures and adopt a proactive, defense-in-depth posture. This requires deploying advanced threat intelligence monitoring, enforcing strict identity controls across all remote endpoints, and continuously auditing network traffic for exfiltration signals. Only by maintaining visibility and control across every stage of the attack lifecycle can organizations protect their critical assets and build resilience against sophisticated cyber extortion campaigns.




Comments