The group behind the Rhysida Ransomware has carried out numerous attacks on critical organizations , such as hospitals, power plants , and schools in the UK, Europe, and the Middle East.

It appeared in May 2023, and within nine months had attacked 77 companies and public organizations, according to the hackers. eSentire's security research team , Threat Response Unit (TRU), studied the attacks and confirmed the authenticity of the victims listed on the data Rhysida ransomware group's
Recent targets of Rhysida attacks include critical infrastructure. Operating as a Ransomware-as-a-Service (RaaS) provider, Rhysida offers its tools and infrastructure to other cybercriminals, who carry out the attacks and then give a portion of the ransom to Rhysida’s developers.
See also: Decryption tool for Rhysida Ransomware!
New findings about Rhysida ransomware and its connection to Vice Society
According to a TRU report (shared with Infosecurity Magazine), similarities were found between the tactics, techniques, and procedures (TTPs) of the Rhysida group and those of Vice Society . This connection had previously been made by Check Point researchers
According to eSentire, Vice Society was particularly active until May 2023. During that time, the Rhysida ransomware appeared. Previously, Vice Society had targeted organizations in the education and healthcare, as did the Rhysida group recently.
Mode of operation and effects of attacks
The Rhysida ransomware group uses double-crossing extortion tactics, like most gangs today. Hackers steal data from targeted systemsbefore encrypting the files. They then demand huge sums of money from victims to regain access to their data and avoid making the stolen information public.
One of the most recent and significant attacks, which used the tactic of double blackmail, was the one on the British Library.
See also: Wolverine: Rhysida ransomware leaks game data
“The Rhysida hackers not only encrypted many of the library’s systems, but also stole 600 gigabytes of information, including personal information related to some of the employees library’s,” eSentire wrote.
Protection from attacks
According to Keegan Keplinger, senior threat researcher at eSentire's TRU, the hackers behind Rhysida are targeting some of a business's most valuable and sensitive data.

Therefore, it is essential to take strong security to protect against ransomware attacks:
One of the most effective methods of protecting against ransomware is user awareness and education . Users should be aware of the risks associated with opening suspicious emails or visiting untrustworthy websites.
See also: Wolverine: Rhysida ransomware leaks game data
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Installing reliable security software is another important method of protection. This software should include malware, ransomware protection, phishing protection, and virus protection.
Also, regularly backing up important data can prevent data loss in the event of a ransomware attack. Backups should be stored in a secure, offline location.
Finally, keeping your operating system and applications up is crucial for protection against ransomware. Updates often include security fixes that can prevent ransomware attacks.
Source: www.infosecurity-magazine.com
