top of page

Rhysida Ransomware Group: Dark Web Data Leak Case Study

  • securedmonk
  • Jun 29
  • 14 min read
Rhysida Ransomware Group: Dark Web Data Leak Case Study | Securedmonk

Executive Summary


The emergence of the Rhysida Ransomware Group in May 2023 signaled a rapid, aggressive shift in the threat landscape, challenging established paradigms of corporate defense. Posing as a benign "cybersecurity team" performing simulated penetration audits, this highly active Cybercrime Group uses specialized payloads to encrypt files and exfiltrate sensitive directories. Rhysida's operations are defined by their uncompromising posture: they target high-value enterprise entities across sectors where operational downtime is intolerable, such as healthcare, education, manufacturing, and government. This Rhysida Case Study analyzes the technical mechanics, dark web operational infrastructure, and victimology of Rhysida, demonstrating how they utilize a dual-pronged approach to maximize extortion leverage.

By combining tactical network intrusions with a sophisticated public Data Leak Site, the group forces victims into a compressed timeline for negotiations. Unlike traditional groups that use data leak sites merely as repository archives, Rhysida operates an interactive, auction-based Rhysida Dark Web Portal to sell stolen corporate assets directly to the highest bidder. This analysis outlines the entire attack sequence, examines the underlying cryptographic vulnerabilities that led to the partial cracking of their Windows payload, and provides structured mitigation strategies to secure modern enterprise networks against this persistent threat.


Rhysida Ransomware Group: Dark Web Data Leak Case Study | Securedmonk


Rhysida Ransomware Group at a Glance (Quick Threat Profile)


To understand Rhysida's positioning within the broader cybercrime ecosystem, a detailed Threat Actor Profile must be established to trace their access vectors, monetization strategies, and core targeting patterns. The table below provides a structured overview of the group's operational parameters:


Attribute

Details

First Detected

May 2023 (Infrastructure prepared as early as March 2023)

Threat Actor Type

Ransomware-as-a-Service (RaaS) operator and extortionist collective

Primary Monetization

Double Extortion Ransomware (Data encryption + public auctions)

Initial Intrusion Vectors

Phishing, compromised VPN credentials, and remote execution vulnerabilities

Key Targets

Healthcare, Academic/Education, Heavy Manufacturing, and Public Services

Exfiltration Strategy

Manual staging using specialized backdoors and cloud exfiltration tools

Cryptographic Standard

ChaCha20 stream cipher wrapped in RSA-4096-OAEP key distribution

Primary Payment Method

Bitcoin (BTC) via customized dark web portals


What makes the Rhysida Ransomware Group different from traditional ransomware groups is their fluid operational model and total lack of ethical boundaries. While legacy syndicates occasionally avoid critical public services like hospitals or schools to bypass aggressive law enforcement pressure, Rhysida purposefully targets these vulnerable networks to exploit their low downtime tolerance. Furthermore, their close relationship with other active threat clusters most notably their documented alignment with actors previously associated with Vice Society allows them to quickly adopt refined tools, specialized initial access brokers, and highly effective lateral movement playbooks.



Understanding Rhysida's Dark Web Leak Site


The core of Rhysida's extortion strategy is the Rhysida Leak Site, a highly structured platform hosted on the Tor network. Unlike simple repositories that list static links to stolen directories, the Rhysida Onion Site is designed to mimic a professional, interactive auction house. This interface is optimized to generate intense public and regulatory pressure, accelerating the victim's timeline for payment.


Homepage Architecture

The homepage of the Rhysida Dark Web Portal features a clean, minimalist layout dominated by the group's signature centipede logo. At the top of the interface, dynamic counters display the number of active, real-time auctions alongside a total count of victims processed by the platform. A prominent input field labeled "Token" allows victims to input the unique cryptographic identifier provided in their ransom note, immediately redirecting them to a private, secure communication portal. This homepage acts as the primary public interface, exposing targeted organizations to the world.


Stolen Data Archive

For victims who refuse to negotiate, the portal maintains a public archive containing fully exfiltrated datasets. Each listing in this archive includes the targeted company's logo, a brief description of their business operations, the total volume of exfiltrated data in gigabytes, and the exact count of files included in the dump. Progress bars are displayed on these listings, showing the percentage of the data that has been uploaded to public servers. Once the upload reaches 100%, the page provides direct links to multi-part, compressed archives hosted on decentralized storage services, making the data accessible to anyone.


Rhysida Ransomware Group: Dark Web Data Leak Case Study | Securedmonk

Live Data Auctions

The defining feature of the site's extortion design is the Rhysida Auction interface. When a new victim is posted to the active Rhysida Victim List, the group initiates a formal countdown timer, usually set to seven days. During this period, the exclusive rights to purchase the stolen data are put up for bidding in a Rhysida Data Auction.


Rhysida Ransomware Group: Dark Web Data Leak Case Study | Securedmonk

The layout displays the starting price denominated in Bitcoin (BTC), the exact time remaining on the clock, and a structured data preview. To maintain high-intensity pressure, the interface includes a comment section where external actors, initial access brokers, and potential buyers can communicate. Rhysida enforces a strict "no reselling" policy, declaring that the highest bidder will be the sole owner of the data, which encourages competition among threat actors and corporate competitors.


Technical Document Previews

To prove the authenticity of their data theft, Rhysida provides high-resolution document previews directly within each auction listing. These previews showcase sensitive internal documents, including architectural blueprints, employee identification cards, legal contracts, and financial audits. By displaying proof of access openly, Rhysida bypasses standard deniability strategies, forcing the victim's executive team to confront the reality of the breach.


Victim Contact and Support Panel

The platform includes an interactive communication panel protected by a custom graphical Captcha system designed to block automated bots and DDoS scraping tools. This portal allows victims to submit comments, exchange files, and negotiate ransom terms directly with Rhysida's support operators. The system also includes direct links to commercial cryptocurrency exchanges, complete with tutorials on how to acquire and transfer Bitcoin, lowering the technical barrier for payment.


Rhysida Ransomware Group: Dark Web Data Leak Case Study | Securedmonk


Attack Lifecycle: How Rhysida Operates

The typical execution flow of a Rhysida Ransomware Attack is a fast, highly organized sequence designed to achieve complete domain compromise before security teams can react. This lifecycle moves systematically through the following phases:


Initial Access

Rhysida avoids highly complex zero-day exploitation for initial entry, relying instead on high-probability, proven entry points. The group frequently utilizes targeted phishing campaigns containing malicious attachments or links designed to harvest user credentials. Additionally, they leverage an Initial Access Broker to purchase legitimate but compromised credentials for external remote services. These are frequently used to log into corporate Virtual Private Network (VPN) devices that lack multi-factor authentication (MFA). In some instances, the group exploits unpatched, public-facing vulnerabilities in security appliances or utilizes sophisticated malvertising campaigns to deliver custom loader payloads.


Payload Delivery & CleanUpLoader Deployment

To establish a resilient beachhead within the target network, Rhysida operators deploy CleanUpLoader (also known as Oyster or Broomstick). Commonly disguised as legitimate utility setups like Microsoft Teams or Google Chrome installers, this C++ based backdoor is frequently signed with fraudulent digital certificates to bypass endpoint detection and response (EDR) agents. Once executed, the backdoor establishes persistence by creating periodic scheduled tasks and communicates with multi-tiered Command and Control (C2) servers via HTTPS, allowing the attackers to download secondary toolsets and run administrative commands.


Privilege Escalation & Reconnaissance

With a backdoor established, the threat actors execute tools to map the target domain and elevate their privileges. They often exploit known administrative configuration flaws or vulnerabilities like Zerologon (CVE-2020-1472) to quickly gain domain administrator rights. Internal reconnaissance is conducted using lightweight utilities, such as Advanced Port Scanner and customized PowerShell scripts, allowing the attackers to map the network architecture and locate high-value assets like Active Directory databases, critical servers, and storage repositories.


Credential Theft & Lateral Movement

Rhysida actively targets authentication material to secure their control over the network. They use utilities to dump the memory of the Local Security Authority Subsystem Service (lsass.exe) to harvest plaintext credentials and Active Directory hashes. In many cases, they target Active Directory domain controllers, utilizing the native ntdsutil.exe utility to extract and dump the entire Active Directory database file (ntds.dit), capturing credential hashes for every user in the organization. Lateral movement is then executed using administrative channels, such as Remote Desktop Protocol (RDP), PsExec, and Windows Remote Management (WinRM).


Staging, Exfiltration, & Encryption Execution

Before launching the encryption routine, Rhysida operators stage and exfiltrate sensitive files. They create dedicated directories on compromised hosts, manually appraise and gather files containing personally identifiable information (PII) and intellectual property, and compress the datasets into multi-part archives.


Exfiltration is conducted using tools like Azure Storage Explorer or rclone to upload the data to attacker-controlled cloud storage accounts. Once exfiltration is verified, the threat actors deploy the ransomware payload across all accessible endpoints and hypervisors, encrypting files, dropping ransom notes, and initiating the dark web publication sequence.



Technical Analysis of Rhysida

A deep Rhysida Ransomware Analysis reveals a payload engineered for high-speed encryption across both enterprise workstations and virtualized hypervisor environments.


Compilation and Tooling Details

The primary Windows payload is compiled as a 32-bit or 64-bit Portable Executable (PE) using MinGW and the GNU Compiler Collection (GCC). For its cryptographic functions, the malware developers avoided writing custom encryption routines, choosing instead to integrate the open-source LibTomCrypt library. This design allows the payload to perform highly optimized, parallelized file locking by spawning threads equivalent to the total number of logical processors on the target system.


Encryption Mechanics

To achieve maximum speed, Rhysida uses a hybrid encryption scheme. The file content is encrypted using the ChaCha20 stream cipher. The unique 32-byte key and 12-byte initialization vector (IV) generated for each file are then encrypted using an embedded, hardcoded RSA-4096 public key with Optimal Asymmetric Encryption Padding (OAEP). This encrypted 512-byte key envelope is appended to the tail of the encrypted file along with a footer containing a file marker.


Furthermore, the payload uses intermittent encryption. For files larger than 1 megabyte (MB), the locker breaks the file into several blocks and only encrypts 1 MB of data within each block, leaving the remaining data unencrypted. This technique corrupts the file header and structure, making it unreadable while drastically reducing the time required to complete the attack.


The Key-Generation Vulnerability and KISA's Decryptor

In early 2024, researchers from Kookmin University and the Korea Internet & Security Agency (KISA) identified a significant implementation flaw in Rhysida's key-generation process. While the developers used LibTomCrypt's secure pseudo-random number generator (PRNG), they initialized the generator's seed using a highly predictable variable: the current system time.


Because the main execution thread compiles a sequential list of files to be encrypted and passes them to parallel sub-threads, the timestamp changes between file executions were highly predictable. This design error allowed researchers to drastically narrow the range of potential seed keys. By tracking the file write sequence on an infected system, the KISA tool can reconstruct the PRNG's state, regenerate the encryption keys, and decrypt the files without paying a ransom.


However, this vulnerability applies strictly to the Windows PE locker. It does not affect the group's Linux, ESXi, or PowerShell-based variants, meaning organizations using virtualized hypervisors cannot rely on this decryption tool.


Evasion and Living-off-the-Land Tactics

Rhysida relies on PowerShell scripts, most notably a script known as SILENTKILL. This script is executed prior to deploying the ransomware payload and is designed to identify and terminate local security software, modify the local firewall rules, clear the Windows event logs, change Active Directory administrative passwords to lock out defenders, and delete local system backups and volume shadow copies using vssadmin.exe. Additionally, some versions of the payload include self-deletion commands to remove the ransomware binary immediately after execution, complicating post-incident forensics.


Command Line Arguments and Features

The Rhysida Windows executable supports several execution parameters, allowing operators to customize the payload's behavior:

-d <path>   Specifies a target directory to encrypt. If omitted, the locker traverses all local drives. [cite: 33]
-sr         Enables self-deletion of the ransomware binary immediately after the encryption run is completed. [cite: 33]
-nobg       Disables the modification of the host wallpaper to the ransom notification. [cite: 33]
-S          Creates a persistent scheduled task named "Rhsd" to run the payload under SYSTEM context.
-md5        Pre-calculates the MD5 file hash prior to encryption (an incomplete utility function). [cite: 33]

MITRE ATT&CK Mapping

The operational behavior of Rhysida throughout an intrusion is mapped to the MITRE ATT&CK framework below:


Tactic

Technique Name

ID

Description / Implementation Details

Initial Access

Phishing: Malicious Link / Attachment

T1566

Delivers malicious email attachments and payload links.

Initial Access

Valid Accounts: External Services

T1078

Authenticates to corporate VPN networks using compromised credentials.

Execution

Command and Scripting Interpreter

T1059.001

Runs PowerShell scripts (SILENTKILL) to terminate services and clear event logs.

Persistence

Scheduled Task/Job: Scheduled Task

T1053.005

Creates persistent tasks named "Rhsd" via command arguments or CleanUpLoader routines.

Privilege Escalation

Exploitation of Remote Services

T1210

Exploits Netlogon vulnerabilities (Zerologon) to gain domain administration.

Defense Evasion

Impair Defenses: Disable Tools

T1562.001

Disables security applications and modifies Active Directory settings.

Defense Evasion

Indicator Removal: File Deletion

T1070.004

Executes PowerShell self-deletion scripts to clean up files after execution.

Credential Access

OS Credential Dumping: LSASS

T1003.001

Uses memory dump utilities like ProcDump on lsass.exe.

Discovery

System Network Connections Discovery

T1049

Runs port scanners and native network commands to identify host machines.

Lateral Movement

Remote Services: Remote Desktop Protocol

T1021.001

Moves laterally between targets using compromised administrative credentials.

Exfiltration

Transfer Data to Cloud Storage

T1567.002

Uses Azure Storage Explorer to upload stolen datasets to cloud storage.

Impact

Data Encrypted for Impact

T1486

Encrypts files using ChaCha20 and appends the .rhysida extension.



A detailed Ransomware Group Analysis demonstrates that Rhysida's targeting strategy is highly opportunistic, focusing on sectors that face high public pressure and regulatory compliance burdens. By targeting these environments, they exploit the high recovery costs and low downtime tolerance of their victims, increasing the likelihood of a payout.


Sector Distribution

The group's victimology focuses heavily on four primary sectors:

  • Healthcare and Public Health (HPH): Rhysida targets hospitals, diagnostic networks, and urgent care clinics, recognizing that systems disruption directly threatens patient safety. Notable attacks include Prospect Medical Holdings and Lurie Children's Hospital.

  • Education and Academic Services: The group frequently targets public school systems and universities, exploiting their limited security budgets and highly distributed network architectures.

  • Government and Public Infrastructure: Attacks on administrative entities, such as the City of Columbus and the Chilean Army, demonstrate the group's willingness to target sovereign government infrastructure.

  • Heavy Manufacturing & Construction: Industrial targets are selected due to their highly integrated supply chains, where a localized system outage can stall production lines and cause significant financial loss.

Geographical Target Patterns

Rhysida's attacks are global, targeting organizations across Europe, North America, and South America. The primary geographic concentrations of verified victims are listed in the table below:


Country Location

Relative Target Weight

Key Vulnerability Characteristics

United States

High (~46% of cases)

Highly reliant on interconnected clinical platforms and vulnerable remote access portals.

United Kingdom

Moderate

Focused on centralized public sector entities and academic institutions.

Germany

Moderate

Heavy targeting of mid-market manufacturing hubs and local public administrations.

Chile / Spain

Moderate

Vulnerable external access points and unpatched remote gateways.



Dark Web Intelligence: What Businesses Can Learn from Leak Sites

For modern security teams, the Rhysida Leak Site is more than just an extortion portal; it is a critical source of Cyber Threat Intelligence. By systematically monitoring the activities on these portals, defenders can extract valuable indicators of compromise and contextual threat data.


Analyzing Stolen Data Assets

When data is uploaded to a Data Leak Site, threat intelligence analysts can evaluate the specific categories of files released during an auction. The typical classifications of leaked assets found on the portal include:

  • Corporate Identity Records: Passport copies, driver's licenses, and HR records. These files provide attackers with material for targeted social engineering campaigns.

  • Internal Network Blueprints: Network architecture maps, Active Directory structures, and asset inventories. These files can be sold to initial access brokers to facilitate follow-on compromises.

  • Financial and Legal Documentation: Proprietary contracts, quarterly tax filings, and insurance policies. This information is highly valuable to industrial competitors.

Early Exfiltration Indicators

Network intelligence research has demonstrated that defenders can track the infrastructure associated with Rhysida long before files are encrypted. By analyzing the multi-tiered C2 domains and payload delivery servers used by CleanUpLoader, security teams can detect ongoing intrusions during the attacker's dwell time.


In multiple cases, network traffic tracking identified victim exfiltration events an average of 30 days before the target's name appeared on the public Rhysida Victim List. This highlights the critical importance of monitoring early indicators of compromise (IOCs) rather than relying solely on file signature detection.



Business Impact Beyond Encryption

The consequences of a Rhysida Ransomware Attack extend far beyond the immediate technical cost of file decryption. When an enterprise is compromised, the downstream operational, financial, and reputational damages can persist for years.


Operational Disruptions

When critical infrastructure is encrypted, organizations are often forced to revert to manual processes. In healthcare environments, hospitals must shut down clinical systems, postpone surgeries, redirect emergency vehicles, and manage patient records on paper. In manufacturing, production lines halt, leading to contractual penalties, supply chain blockages, and lost market position.


Regulatory Fines and Compliance Exposures

Exfiltrating sensitive data triggers strict regulatory reporting requirements. Under frameworks like HIPAA or GDPR, organizations face severe financial penalties for failing to secure personally identifiable information (PII) and protected health information (PHI). Compromised organizations also face significant legal risks, including long-tail class-action lawsuits and regulatory audits that drain capital and resources.


Brand Damage and Trust Erosion

When customer and client data is publicly auctioned on a dark web portal, brand reputation is severely damaged. The exposure of proprietary designs, corporate correspondence, and employee records erodes stakeholder trust. This loss of confidence can lead to customer churn, decreased enterprise valuation, and increased difficulty in securing future business partnerships.



Detection & Defense Strategies

Organizations must implement a multi-layered security framework designed to prevent initial access, limit lateral movement, and quickly isolate compromise indicators.


Strategic Prevention Measures

To effectively mitigate the risk of initial compromise, the following baseline controls should be implemented:

  • Enforce Strict Identity Protections: Deploy phishing-resistant Multi-Factor Authentication (MFA) across all remote access vectors, particularly VPN devices, email portals, and administrative access points.

  • Vulnerability and Patch Management: Maintain a rigorous patching cadence for all public-facing services, particularly VPN appliances and remote management gateways.

  • Application Control and Access Whitelisting: Define strict application policies to prevent the execution of dual-use utilities, such as unauthorized remote monitoring and management (RMM) tools.

  • Strict Network Segmentation: Separate critical operations databases and internal active directory structures from standard corporate workstations to limit lateral movement.

Key Detection Signals

Security Operations Centers (SOC) should configure their monitoring tools to alert on the following threat behaviors:

  • Unusual Process Access: Alert on unauthorized attempts by non-system processes to access the memory of lsass.exe to create memory dumps.

  • Suspicious Active Directory Activity: Monitor execution patterns of administrative tools like ntdsutil.exe when utilized to export directory data.

  • Abuse of Administrative Tools: Track command execution patterns involving PsExec, RDP connections using administrative credentials, and anomalous PowerShell scripts.

  • Anomalous Cloud Traffic Outflows: Monitor massive, unauthorized data transfers to cloud platforms, particularly when utilizing utilities like rclone or Azure Storage Explorer.



Indicators of Compromise (IOCs)

Defenders should screen their environments for the following verified indicators of compromise associated with Rhysida operations:


Known Executable Hashes (SHA-256)

The following hashes represent known malicious binaries associated with Rhysida ransomware payloads, CleanUpLoader, and SILENTKILL PowerShell scripts:


Indicator Type

Cryptographic Hash (SHA-256)

Associated Malware / Tool Profile

File Hash

f0668ce925f36ff7f3359b0ea47e3fa243af13cd6ad9661dfccc9ff79fb4f1cc

CleanUpLoader Backdoor Executable

File Hash

11af4566539ad3224e968194c7a9ad7b596460d8f6e423fc62d1ea5fc0724326

CleanUpLoader Execution Payload

File Hash

f0a6b89ec7eee83274cd484cea526b970a3ef28038799b0a5774bb33c5793b55

Installer Dropper Payload

File Hash

97766464d0f2f91b82b557ac656ab82e15cae7896b1d8c98632ca53c15cf06c4

Staging batch script (S_1.bat)

File Hash

918784e25bd24192ce4e999538be96898558660659e3c624a5f27857784cd7e1

Execution script for conhost.exe (S_2.bat)

File Hash

e5d4a2e704ee880273aa4e8114fe9927b0019ff8

Rhysida Ransomware Encryptor Payload (conhost.exe)

File Hash

4e34b9442f825a16d7f6557193426ae7a18899ed46d3b896f6e4357367276183

File Extension Blocklist Script (1.ps1)

File Hash

a864282fea5a536510ae86c77ce46f7827687783628e4f2ceb5bf2c41b8cd3c6

Rhysida Windows Locker Binary

Operational Network and Host Indicators

The following domains, IPs, and system markers are associated with Rhysida C2 infrastructure and deployment scripts:


Indicator Type

Specific Target Value

Detailed Threat Context

IP Address

Exfiltration Destination / Transport Host

IP Address

Known Command & Control Target Node

IP Address

Attacker Infrastructure Gateway

Domain

CleanUpLoader Initial Payload Delivery Site

Domain

Typosquatted Team impersonation URL

Domain

Impersonated PuTTY Landing Domain for Loader Delivery

File Name

CriticalBreachDetected.pdf

Hardcoded ransom note dropped in encrypted directories

File Extension

.rhysida

Appended to encrypted files



Key Lessons for Security Leaders

Analyzing the operations of the Rhysida Ransomware Group highlights several critical lessons for enterprise security leadership:

  • Backups Alone Are Not Enough: Legacy disaster recovery strategies that rely solely on system restoration fail to address the risk of data exfiltration. When a double-extortion actor captures sensitive files, the threat of public exposure remains a powerful lever even if system operations can be restored.

  • Early Exfiltration Detection Is Key: Real security resilience requires detecting attacks during the initial intrusion and staging phases, well before system encryption begins.

  • Identity Is the New Perimeter: Legitimate credentials stolen by initial access brokers bypass traditional perimeter security controls. Strengthening access controls, monitoring authentication anomalies, and enforcing least-privilege access are essential to securing the enterprise.


Conclusion

The Rhysida Ransomware Group continues to be a highly disruptive force in the cyber threat landscape, using refined double-extortion strategies to target critical infrastructure worldwide. By combining specialized loaders with an interactive public auction site, the group generates intense pressure to force quick payment decisions. While vulnerabilities in their payload's key-generation process have allowed defenders to develop decryption tools, these tools do not protect virtualized hypervisor environments or prevent the exposure of exfiltrated data.


To defend against this threat, enterprises must move beyond reactive security measures and adopt a proactive, defense-in-depth posture. This requires deploying advanced threat intelligence monitoring, enforcing strict identity controls across all remote endpoints, and continuously auditing network traffic for exfiltration signals. Only by maintaining visibility and control across every stage of the attack lifecycle can organizations protect their critical assets and build resilience against sophisticated cyber extortion campaigns.

Comments


bottom of page