Back to Intelligence

RHYSIDA Ransomware Gang: 3 New Leak-Site Claims Spanning Energy, Technology & Legal Sectors — Targeting Analysis & Detection Rules

SA
Security Arsenal Team
October 2, 2026
13 min read

Classification: TLP:CLEAR | Publication Date: 2026-10-03 | Source: ransomware.live leak-site monitoring | Nature of data: Unverified threat-actor claims

RHYSIDA Ransomware Gang: 3 New Leak-Site Claims Spanning Energy, Technology & Legal Sectors

Executive Summary

Between 2026-09-30 and 2026-10-02, the RHYSIDA ransomware operation published three new listings on its dark web leak site, naming organizations in the Energy & Utilities, Technology, and Professional Services sectors across Sweden, Germany, and the United States. Per our sourcing rules, these are claims made by a criminal actor, not confirmed breaches. All three listings were independently observed by two separate leak-site crawlers, which confirms the gang made the claims — it does not confirm any intrusion occurred.

The named organizations are:

  • Electro Heat Sweden AB (Energy & Utilities, SE) — listed 2026-10-02
  • clicks digital GmbH Information (Technology, DE) — listed 2026-09-30
  • Law Offices of R. David Williams, P.A. (Professional Services, US) — listed 2026-09-30

The sector spread — a utility, a digital/technology firm, and a law practice — is consistent with RHYSIDA's historical opportunism: the group has never been sector-loyal, but it disproportionately lists mid-sized organizations where a single perimeter weakness (VPN, RDP, or a phished credential) yields full domain compromise. Defenders in these verticals should treat this as a sector-exposure signal, not evidence that the named organizations are managing incidents.

Sourcing & Verification

  • 3 of 3 listings in this report were independently observed by a second leak-site crawler; 0 rest on a single source. Multi-source observation confirms the threat actor published the claim — nothing more.
  • Inclusion in this briefing reflects the threat actor's accusation and is NOT confirmation of a breach. No corroboration tier available to us — or to any external leak-site monitor — can verify an intrusion. Only the named organization or its regulator can do that.
  • A named organization may dispute a listing. A denial is likewise not proof the claim is false: disclosure obligations vary by jurisdiction and sector, and not every incident is reportable. Neither silence nor denial settles the question, and we do not treat either as dispositive.
  • Security Arsenal will publish corrections if warranted and welcomes contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — RHYSIDA

Aliases / branding: RHYSIDA (stylized "Rhysida"). No widely attributed rebrand; the operation has maintained consistent leak-site branding since emerging in mid-2023. Some reporting associates its operators with the remnants of earlier ransomware crews, but attribution remains contested.

Operating model: RHYSIDA functions as a semi-closed operation — it has run RaaS-style affiliate recruitment but with a far smaller, more curated affiliate base than LockBit or BlackCat. The core group appears to retain control of negotiation and leak-site publication, which explains its comparatively low posting volume (3 listings in the last 100-posting window covered here).

Ransom demands: Historically in the low-to-mid six figures USD for SMB victims, scaling into seven figures for larger enterprises and public-sector-adjacent targets. RHYSIDA frequently lists data for auction-style sale when negotiations stall, and has used countdown timers on its leak site to pressure victims.

Initial access methods (historical TTPs):

  • Phishing with malicious attachments/links — the most consistently reported vector, often delivering loaders that stage Cobalt Strike.
  • External remote services — exploitation of internet-facing VPN concentrators and gateways lacking MFA; valid-account abuse of RDP exposed to the internet.
  • Valid accounts — credential reuse from stealer logs and prior breaches.
  • Vulnerability exploitation — opportunistic exploitation of edge-device and virtualization flaws shortly after public disclosure.

Extortion model: Double extortion is standard — data is staged and exfiltrated (frequently via Rclone or MEGA) before encryption, and non-payers are listed on the leak site with escalating data teasers.

Dwell time: Observed dwell time typically ranges from 2 to 10 days between initial access and encryption, though phishing-driven intrusions have detonated in under 48 hours. The window between exfiltration and encryption is often less than 24 hours — detection in the staging phase is the last reliable intervention point.

Current Campaign Analysis

Sectors claimed: Energy & Utilities (1), Technology (1), Professional Services (1). Three listings across three unrelated sectors in three countries reads as opportunistic affiliate activity rather than a focused vertical campaign — but the presence of an energy/utility claim warrants elevated attention given RHYSIDA's past willingness to list critical-infrastructure-adjacent organizations.

Geographic concentration: SE, DE, US — no concentration; this is a transatlantic spread consistent with a broad phishing or credential-access pipeline rather than region-specific targeting.

Victim profile: Based on sector and naming, all three organizations appear to sit in the small-to-mid-size band (roughly 10–250 employees; estimated revenue from low seven figures to ~$50M). This is RHYSIDA's sweet spot: organizations large enough to pay, small enough to lack 24/7 SOC coverage and mature identity controls.

Posting cadence: 3 listings in ~72 hours is a modest but noticeable uptick for this group, which often goes weeks between posts. It may indicate a batch of access from a single initial-access broker or a phishing wave maturing into negotiations — but with three data points, do not over-extrapolate.

CVE linkage (hypothesis only): We have no evidence tying any specific CVE to any named listing above. That said, several vulnerabilities on the current CISA KEV list with confirmed ransomware use map directly onto RHYSIDA's known access playbook and represent plausible sector-level exposure:

  • CVE-2026-50751 (Check Point Security Gateway improper authentication) — edge-device compromise is a classic RHYSIDA entry point.
  • CVE-2026-20316 (Cisco Secure FMC hard-coded password) — management-plane takeover enables firewall disablement ahead of lateral movement.
  • CVE-2026-59310 (VMware vCenter path traversal) — hypervisor access aligns with RHYSIDA's observed preference for encrypting ESXi-hosted workloads at scale.
  • CVE-2026-63077 (JetBrains TeamCity deserialization) and CVE-2026-48027 (Nx Console supply-chain compromise) — relevant to technology-sector victims with CI/CD pipelines, and consistent with the group's interest in developer infrastructure as a data-exfil source.

Treat these as prioritized patching hypotheses, not attribution.

Detection Engineering

The following analytics target RHYSIDA's documented playbook: phishing-driven macro/loader execution, exploitation of edge remote access, PsExec/WMI lateral movement, Cobalt Strike staging, shadow-copy deletion, and Rclone-style exfiltration prior to encryption.

YAML
---
title: RHYSIDA - Phishing Loader Child Process Spawn From Office
description: Detects Office applications spawning script interpreters or unsigned binaries, consistent with RHYSIDA phishing-delivered loaders staging Cobalt Strike.
id: 7f3a1c2e-rhys-0001
status: experimental
author: Security Arsenal Threat Intel
logsource:
  category: process_creation
  product: windows
  definition: 'Requires Sysmon Event ID 1 or equivalent process creation auditing with command line logging.'
detection:
  selection_parent:
    ParentImage|endswith:
      - '\winword.exe'
      - '\excel.exe'
      - '\powerpnt.exe'
      - '\outlook.exe'
  selection_child:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\mshta.exe'
      - '\rundll32.exe'
      - '\regsvr32.exe'
      - '\cmd.exe'
  condition: selection_parent and selection_child
falsepositives:
  - Legitimate macro-enabled templates in finance/legal workflows
level: high
tags:
  - attack.initial_access
  - attack.t1566.001
  - attack.t1204.002
---
title: RHYSIDA - Lateral Movement via PsExec Service or WMI Process Spawn
description: Detects PsExec-style service execution and WMI remote process creation, both observed in RHYSIDA intrusions during lateral movement ahead of encryption.
id: 7f3a1c2e-rhys-0002
status: experimental
author: Security Arsenal Threat Intel
logsource:
  category: process_creation
  product: windows
  definition: 'Requires Sysmon Event ID 1 or equivalent process creation auditing.'
detection:
  selection_psexec:
    Image|endswith:
      - '\psexec.exe'
      - '\psexesvc.exe'
      - '\paexec.exe'
      - '\remcom.exe'
  selection_wmi:
    ParentImage|endswith: '\wmiprvse.exe'
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\rundll32.exe'
  condition: 1 of selection_*
falsepositives:
  - Admin tooling; baseline authorized PsExec/WMI usage by hostname and account
level: high
tags:
  - attack.lateral_movement
  - attack.t1021.002
  - attack.t1047
  - attack.t1569.002
---
title: RHYSIDA - Pre-Encryption Staging - Shadow Copy Deletion or Rclone Execution
description: Detects Volume Shadow Copy deletion and Rclone-style exfiltration tooling, the final staging steps RHYSIDA performs before detonation.
id: 7f3a1c2e-rhys-0003
status: experimental
author: Security Arsenal Threat Intel
logsource:
  category: process_creation
  product: windows
  definition: 'Requires Sysmon Event ID 1 or equivalent process creation auditing with command line logging.'
detection:
  selection_vss:
    - Image|endswith: '\vssadmin.exe'
      CommandLine|contains:
        - 'delete shadows'
        - 'resize shadowstorage'
    - Image|endswith: '\wmic.exe'
      CommandLine|contains: 'shadowcopy delete'
    - Image|endswith: '\bcdedit.exe'
      CommandLine|contains: 'recoveryenabled no'
  selection_rclone:
    - Image|contains: '\rclone'
    - CommandLine|contains:
        - 'rclone copy'
        - 'rclone sync'
        - 'rclone move'
  condition: 1 of selection_*
falsepositives:
  - Veeam/backup maintenance windows for vssadmin resize; legitimate Rclone use in IT
level: critical
tags:
  - attack.impact
  - attack.t1490
  - attack.exfiltration
  - attack.t1567.002
---
title: RHYSIDA - Suspicious Authentication Burst on VPN or RDP (Brute Force / Password Spray)
description: Detects high-volume failed logons followed by success on edge authentication paths, consistent with RHYSIDA valid-account access via VPN/RDP.
id: 7f3a1c2e-rhys-0004
status: experimental
author: Security Arsenal Threat Intel
date: 2026/10/03
modified: 2026/10/03
logsource:
  product: windows
  service: security
  definition: 'Requires Windows Security Event IDs 4624/4625 auditing on VPN gateways, RD Gateway, and domain controllers.'
detection:
  selection_failed:
    EventID: 4625
  selection_success:
    EventID: 4624
    LogonType:
      - 3
      - 10
  condition: selection_failed or selection_success
falsepositives:
  - Misconfigured service accounts; VPN client retry storms
level: medium
tags:
  - attack.credential_access
  - attack.t1110
  - attack.initial_access
  - attack.t1078
---

The following Microsoft Sentinel hunt query pivots on RHYSIDA's pre-encryption staging behavior: an account that newly touches multiple hosts via SMB/admin shares, spawns remote execution tooling, and then initiates shadow-copy or backup tampering — the signature sequence of an operator preparing detonation.

KQL — Microsoft Sentinel / Defender
// RHYSIDA pre-detonation hunt: new lateral movement + staging tampering per account/host
let Lookback = 7d;
let SuspiciousTools = dynamic(["psexec", "psexesvc", "paexec", "wmic", "rclone", "megacmd", "vssadmin", "bcdedit", "nltest", "adfind", "sharphound", "bloodhound"]);
let ProcEvents =
    DeviceProcessEvents
    | where TimeGenerated >= ago(Lookback)
    | extend ProcLower = tolower(FileName), CmdLower = tolower(ProcessCommandLine)
    | where ProcLower has_any (SuspiciousTools) or CmdLower has_any ("shadowcopy", "delete shadows", "recoveryenabled no", "rclone copy", "rclone sync", "\\admin$");
let TamperEvents =
    ProcEvents
    | where CmdLower has_any ("delete shadows", "shadowcopy delete", "recoveryenabled no", "resize shadowstorage")
    | summarize TamperCount=count(), TamperCmds=make_set(ProcessCommandLine) by DeviceName, InitiatingProcessAccountName, bin(TimeGenerated, 1h);
let LateralEvents =
    DeviceNetworkEvents
    | where TimeGenerated >= ago(Lookback)
    | where RemotePort in (445, 135, 3389, 5985)
    | summarize RemoteHosts=dcount(RemoteIP), RemoteIPSet=make_set(RemoteIP, 20) by DeviceName, InitiatingProcessAccountName, bin(TimeGenerated, 1h)
    | where RemoteHosts >= 5;
LateralEvents
| join kind=inner TamperEvents on DeviceName, InitiatingProcessAccountName, TimeGenerated
| project TimeGenerated, DeviceName, InitiatingProcessAccountName, RemoteHosts, RemoteIPSet, TamperCount, TamperCmds
| order by TimeGenerated desc;
// Tuning: raise RemoteHosts threshold in environments with heavy admin automation;
// suppress known backup/service accounts that legitimately run vssadmin.

The following rapid-response PowerShell checks the three fastest indicators of a RHYSIDA-style pre-detonation posture on a Windows estate: recently created scheduled tasks (persistence), shadow copy tampering, and internet-exposed RDP configuration.

PowerShell
# RHYSIDA Rapid Triage — run elevated; outputs findings to console and CSV
$Out = @()

# 1) Scheduled tasks created or modified in the last 7 days (persistence/staging)
$Cutoff = (Get-Date).AddDays(-7)
$Tasks = Get-ScheduledTask | ForEach-Object {
    try { $info = $_ | Get-ScheduledTaskInfo; [PSCustomObject]@{
        Check='ScheduledTask'; Name=$_.TaskName; Path=$_.TaskPath
        Author=$_.Author; LastRun=$info.LastRunTime; NextRun=$info.NextRunTime
        Action=($_.Actions | ForEach-Object { "$($_.Execute) $($_.Arguments)" }) -join '; '
    } } catch {}
} | Where-Object { $_.Action -match 'powershell|cmd|wscript|mshta|rundll32|regsvr32|%temp%|%appdata%' }
$Out += $Tasks

# 2) Volume Shadow Copy status (should be non-empty on servers)
$Shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
$Out += [PSCustomObject]@{ Check='ShadowCopies'; Name=($ Shadows | Measure-Object).Count
    Path=''; Author=''; LastRun=$null; NextRun=$null
    Action=($(if (-not $Shadows) { 'WARNING: No shadow copies present — possible vssadmin deletion' } else { 'OK' })) }

# 3) Recent vssadmin/wmic/bcdedit execution evidence via Prefetch
$Prefetch = Get-ChildItem 'C:\Windows\Prefetch' -ErrorAction SilentlyContinue |
    Where-Object { $_.LastWriteTime -gt $Cutoff -and $_.Name -match 'VSSADMIN|WMIC|BCDEDIT|RCLONE|PSEXEC' }
$Out += ($Prefetch | ForEach-Object { [PSCustomObject]@{ Check='Prefetch'; Name=$_.Name
    Path=$_.FullName; Author=''; LastRun=$_.LastWriteTime; NextRun=$null
    Action='Recent execution of tamper/lateral-movement binary' } })

# 4) RDP exposure: enabled + NLA status + listening port
$RdpEnabled = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -ErrorAction SilentlyContinue).fDenyTSConnections
$Nla = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -ErrorAction SilentlyContinue).UserAuthentication
$Out += [PSCustomObject]@{ Check='RDP'; Name=($(if ($RdpEnabled -eq 0) { 'RDP ENABLED' } else { 'RDP disabled' }))
    Path=''; Author=''; LastRun=$null; NextRun=$null
    Action="NLA=$(if ($Nla -eq 1) {'on'} else {'OFF — harden immediately'})" }

$Out | Format-Table -AutoSize
$Out | Export-Csv ".\rhysida_triage_$(Get-Date -Format 'yyyyMMdd_HHmm').csv" -NoTypeInformation
Write-Host "`nIf ShadowCopies=0 or unexpected tamper binaries appear, treat as PRE-DETONATION: isolate host from network now." -ForegroundColor Red

Incident Response Priorities

T-minus detection checklist (before encryption fires):

  1. vssadmin delete shadows, wmic shadowcopy delete, or bcdedit ... recoveryenabled no anywhere in the estate — treat as imminent detonation.
  2. New or renamed binaries matching Rclone/MEGAcmd/WinSCP in %TEMP%, %APPDATA%, or C:\ProgramData, especially with recent large outbound transfers.
  3. PsExec service installation (Event ID 7045 with PSEXESVC) or wmiprvse.exe spawning shells on hosts that admins don't normally touch.
  4. Discovery tooling bursts: nltest /dclist, net group "Domain Admins", ADFind/SharpHound execution.
  5. Backup platform anomalies: disabled backup jobs, deleted snapshots, or new logins to Veeam/backup consoles.
  6. New local/domain accounts or group membership changes, particularly to Domain Admins or Backup Operators.
  7. Any of the KEV-listed exposures (Check Point, Cisco FMC, vCenter) showing authentication from unexpected sources.

Assets RHYSIDA historically prioritizes for exfiltration:

  • HR and identity stores: personnel records, passports/IDs, payroll exports.
  • Legal and contractual material: client files, litigation documents, NDAs (acute risk for the professional-services listing pattern).
  • Financial data: banking records, invoices, tax documents.
  • Email archives of executives and finance staff.
  • Source code, build artifacts, and CI/CD secrets for technology targets — relevant given the TeamCity/Nx exposure themes on the KEV list.
  • Operational/schematic data in energy-sector contexts.

Containment actions, ordered by urgency:

  1. Isolate, don't power off any host showing shadow-copy deletion or mass file renames — preserve memory for forensic capture.
  2. Disable the suspected compromised accounts and force enterprise-wide credential resets, prioritizing domain admins, VPN accounts, and service accounts.
  3. Block egress to known exfil destinations (rclone endpoints, MEGA, anonymous file-sharing) at the proxy/firewall.
  4. Segment backup infrastructure off the production network immediately; verify offline/immutable backups are intact before assuming recovery is possible.
  5. Disable RDP externally and restrict 445/135/5985 laterally via host firewall policies.
  6. Engage IR retainer and preserve VPN/firewall/EDR logs before rotation — RHYSIDA dwell time means the initial access artifact is often still recoverable.

Hardening Recommendations

Immediate (24 hours):

  • Patch or mitigate the KEV edge exposures: Check Point Security Gateway (CVE-2026-50751) and Cisco Secure FMC (CVE-2026-20316). If patching is blocked, apply vendor mitigations and restrict management-plane access to allow-listed admin hosts.
  • Enforce MFA on all remote access — VPN, RDP gateways, and webmail. RHYSIDA's phishing/credential pipeline collapses without phishable single-factor auth.
  • Block Office child processes via ASR rules (Block all Office applications from creating child processes) and enable attack surface reduction for script-based payload execution.
  • Deploy the Sigma rules and Sentinel query above and alert on any shadow-copy deletion as P1.
  • Audit scheduled tasks and services created in the last 14 days; remove unauthorized persistence.
  • Restrict Rclone/MEGA/unauthorized sync tools via application control (WDAC/AppLocker) and proxy categorization.

Short-term (2 weeks):

  • Segment the estate: isolate backup infrastructure on a separate management plane with dedicated credentials; implement immutable/offline backup copies with tested restore.
  • Privileged access overhaul: tiered admin model, LAPS for local admin passwords, PAWs for domain administration, and elimination of standing Domain Admin usage.
  • vCenter/ESXi hardening: patch CVE-2026-59310, isolate hypervisor management interfaces, enable ESXi shell lockdown, and snapshot backup datastores immutably.
  • CI/CD protection for technology-sector organizations: patch TeamCity (CVE-2026-63077), rotate CI secrets, and verify integrity of developer tooling against supply-chain tampering (CVE-2026-48027).
  • Egress control: default-deny outbound for servers, with explicit allow-lists; alert on any server initiating cloud-storage uploads.
  • Tabletop the T-minus checklist with your SOC and IR provider so a shadow-copy deletion alert triggers containment in minutes, not hours.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.