Classification: TLP:CLEAR | Publication Date: 2026-10-10 | Source: ransomware.live leak-site monitoring | Nature of data: Unverified threat-actor claims
RHYSIDA Ransomware Gang: 3 New Leak-Site Claims — US Professional Services & Government Targeting Analysis
Executive Summary
Between 2026-10-09 and 2026-10-10, the RHYSIDA ransomware operation posted three new entries to its dark web leak site, naming three United States-based organizations: Gress Clark Young & Schoepper (Professional Services), Anne Arundel County (Government & Defense), and RealManage (Professional Services). These are claims made by a criminal extortion operation — inclusion on a leak site is an accusation, not a confirmed breach. Only the named organizations or their regulators can confirm whether an intrusion occurred.
That said, leak-site telemetry is operationally useful. The concentration of RHYSIDA claims in US professional services and local government aligns with the group's established victimology: mid-market organizations with sensitive data holdings, constrained security budgets, and high-pressure incentive to resolve incidents quietly. Security teams in these sectors — and any organization running VMware vCenter, Check Point gateways, Cisco FMC, or JetBrains TeamCity infrastructure — should treat this bulletin as a trigger to validate the detection content below.
Sourcing & Verification
This briefing is built from ransomware.live leak-site monitoring and must be read with the following caveats:
- 3 of 3 listings covered in this bulletin were independently observed by a second leak-site crawler (MULTI-SOURCE). 0 listings rest on a single source only.
- Multi-source corroboration confirms only that the gang published the claim. It does not confirm that any breach, intrusion, or data theft occurred at any named organization.
- A named organization may dispute a listing. A denial is likewise not proof the claim is false — disclosure obligations vary by jurisdiction, and not every incident is reportable. Neither silence nor denial settles the question.
- No tier in this dataset confirms a breach. Only the organization itself or its regulator can do that.
- Security Arsenal will publish corrections to this briefing if warranted, and welcomes contact from any named organization at security@securityarsenal.com.
Threat Actor Profile — RHYSIDA
Aliases / branding: RHYSIDA (stylized "Rhysida"). The group surfaced in mid-2023 and has sustained a steady operational tempo since. Analysts have noted tooling and tradecraft overlap with elements of the former Vice Society ecosystem, though this attribution remains assessed rather than proven.
Operating model: RHYSIDA operates as a closed group rather than a broad Ransomware-as-a-Service affiliate program. A small core team conducts intrusions directly, which produces more consistent TTPs than franchise-style RaaS operations and makes detection engineering more durable.
Ransom demands: Historically in the mid six to low seven figures (USD), scaled to victim revenue and sector. Government and professional services victims typically see demands calibrated to what the gang assesses as payable without triggering insurer or law-enforcement escalation.
Initial access methods (historical, sector-level):
- Phishing with malicious attachments/links, frequently leading to Cobalt Strike deployment
- Exploitation of internet-facing edge services — VPN concentrators, firewalls, and remote access infrastructure
- Valid account abuse, including credentials purchased or harvested prior to intrusion; the group has been observed operating in environments lacking phishing-resistant MFA
- Known exploitation of publicly exposed RDP and legacy VPN appliances in past campaigns
Extortion model: Classic double extortion — data exfiltration before encryption, with leak-site publication (and countdown timers) used as pressure. RHYSIDA is also known for auction-style disposition of data from victims who refuse to pay.
Dwell time: Observed dwell time from initial access to detonation typically ranges from days to roughly two weeks, with data staging and exfiltration occurring in the final 48–96 hours. This dwell window is the defender's opportunity: the detection content below targets exactly that pre-detonation phase.
Current Campaign Analysis
Targeted sectors
From the last 100 RHYSIDA leak-site postings, the three most recent claims cluster into two sectors:
- Professional Services (2 claims): Gress Clark Young & Schoepper; RealManage
- Government & Defense (1 claim): Anne Arundel County
Geographic concentration
All three claimed victims are United States-based. RHYSIDA has historically concentrated on the US and Western Europe, and this batch is consistent with that pattern.
Victim profile
The named organizations fit RHYSIDA's established mid-market profile: regional law/professional services practices, property management operations, and county-level government entities. Revenue estimates for organizations in these segments typically fall in the tens to low hundreds of millions USD — large enough to hold sensitive PII, financial records, and client data worth extorting, but often operating with lean security staffing and legacy remote-access infrastructure.
Posting frequency and escalation
Three postings across two days (2026-10-09 through 2026-10-10) represents a compressed cluster rather than a steady drip. RHYSIDA commonly batches listings, which may indicate either a coordinated intrusion campaign against a shared exposure class, or a backlog of intrusions being weaponized simultaneously for negotiation pressure. Defenders should treat clustered postings as a signal that a common access vector may be in active use.
CVE exposure context (hypothesis — no victim linkage)
We have no evidence linking any specific CVE to any of the named organizations. However, the following CISA KEV entries — all confirmed as ransomware-exploited — represent plausible sector-level exposure consistent with RHYSIDA's known preference for edge-device and infrastructure exploitation, and should be patched on priority regardless of this campaign:
- CVE-2026-50751 — Check Point Security Gateway improper authentication (IKEv1). Edge VPN/firewall compromise is a documented RHYSIDA-style entry vector.
- CVE-2026-20316 — Cisco Secure Firewall Management Center hard-coded password. Management-plane compromise enables broad lateral reach.
- CVE-2026-59310 — Broadcom VMware vCenter path traversal. Hypervisor control-plane access aligns with pre-encryption staging and mass-ESXi encryption playbooks.
- CVE-2026-63077 — JetBrains TeamCity deserialization. CI/CD compromise enables supply-chain-style downstream access and credential theft at scale.
- CVE-2026-48027 — Nx Console embedded malicious code. Developer-tooling compromise as an initial foothold.
Treat these as hypotheses about where this actor class hunts, not as forensic findings about the named organizations.
Detection Engineering
The Sigma rules below target RHYSIDA's known tradecraft: VPN/edge access anomalies, phishing-driven execution, Cobalt Strike-style staging, PsExec/WMI lateral movement, and pre-encryption shadow copy tampering. Tune thresholds to your environment before production deployment.
---
title: Suspicious Execution from User Profile Directories - Phishing Dropper Pattern
id: 7a1e2b30-9c41-4f2e-b8a1-rhysida00001
status: experimental
description: Detects execution of binaries or scripts from user-writable directories consistent with phishing-delivered payloads observed in RHYSIDA intrusions (Cobalt Strike staging, macro-launched payloads)
author: Security Arsenal Threat Intelligence
references:
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-319a
date: 2026/10/10
logsource:
category: process_creation
product: windows
detection:
selection_path:
Image|contains:
- '\AppData\Local\Temp\'
- '\AppData\Roaming\'
- '\Users\Public\'
- '\ProgramData\Microsoft\'
selection_ext:
Image|endswith:
- '.exe'
- '.dll'
- '.ps1'
- '.bat'
- '.hta'
filter_parents:
ParentImage|endswith:
- '\winword.exe'
- '\excel.exe'
- '\outlook.exe'
- '\wscript.exe'
- '\mshta.exe'
condition: selection_path and selection_ext and filter_parents
level: high
tags:
- attack.execution
- attack.t1059
- attack.t1204
---
title: PsExec or WMI Remote Service Creation - Lateral Movement
id: 7a1e2b30-9c41-4f2e-b8a1-rhysida00002
status: experimental
description: Detects remote service creation and ADMIN$ share usage patterns consistent with PsExec-style lateral movement and WMI-based remote execution used during RHYSIDA pre-encryption staging
date: 2026/10/10
author: Security Arsenal Threat Intelligence
logsource:
product: windows
service: system
detection:
selection_service:
EventID: 7045
selection_names:
ServiceName|contains:
- 'PSEXESVC'
- 'REMComSvc'
selection_binary:
ImagePath|contains:
- 'ADMIN$'
- '\\Pipes\\'
condition: selection_service and 1 of selection_names or selection_binary
level: critical
tags:
- attack.lateral_movement
- attack.t1021.002
- attack.t1569.002
---
title: Volume Shadow Copy Deletion via vssadmin or wmic - Pre-Ransomware Staging
id: 7a1e2b30-9c41-4f2e-b8a1-rhysida00003
status: experimental
description: Detects deletion or resizing of Volume Shadow Copies and boot configuration tampering, a near-universal precursor to ransomware detonation including RHYSIDA operations
date: 2026/10/10
author: Security Arsenal Threat Intelligence
logsource:
category: process_creation
product: windows
detection:
selection_vss:
- Image|endswith: '\vssadmin.exe'
CommandLine|contains:
- 'delete shadows'
- 'resize shadowstorage'
- Image|endswith: '\wmic.exe'
CommandLine|contains: 'shadowcopy delete'
- Image|endswith: '\bcdedit.exe'
CommandLine|contains:
- 'recoveryenabled no'
- 'ignoreallfailures'
condition: selection_vss
level: critical
tags:
- attack.impact
- attack.t1490
- attack.t1562
The following Sentinel hunt query surfaces pre-ransomware staging behavior: mass file access followed by outbound transfer to rare external destinations, combined with shadow copy tampering — the signature of the exfiltration phase that precedes RHYSIDA encryption.
// RHYSIDA-style pre-ransomware staging hunt: shadow tampering + suspicious remote execution + exfil indicators
let Lookback = 7d;
let ShadowTampering =
DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where ProcessCommandLine has_any ("delete shadows", "shadowcopy delete", "resize shadowstorage", "recoveryenabled no")
| project ShadowTime=TimeGenerated, DeviceName, AccountName, ShadowCmd=ProcessCommandLine;
let RemoteExec =
DeviceNetworkEvents
| where TimeGenerated > ago(Lookback)
| where RemotePort in (445, 135) and ActionType == "ConnectionSuccess"
| summarize SMBConnections=count(), DistinctTargets=dcount(RemoteIP) by DeviceName, InitiatingProcessFileName, bin(TimeGenerated, 1h)
| where DistinctTargets > 10; // fan-out consistent with PsExec/WMI sweeps
let RareOutbound =
DeviceNetworkEvents
| where TimeGenerated > ago(Lookback)
| where RemoteIPType == "Public"
| summarize BytesEstimate=count() by DeviceName, RemoteUrl, InitiatingProcessFileName
| where BytesEstimate > 500; // sustained outbound sessions to a single host
ShadowTampering
| join kind=inner (RemoteExec) on DeviceName
| join kind=leftouter (RareOutbound) on DeviceName
| project DeviceName, AccountName, ShadowCmd, ShadowTime, DistinctTargets, SMBConnections, RemoteUrl, InitiatingProcessFileName
| sort by ShadowTime asc
The following rapid-response script audits for the three most common pre-detonation artifacts: shadow copy manipulation, recently created scheduled tasks, and exposed RDP configuration. Run it on any host flagged by the queries above.
# Security Arsenal - Rapid Ransomware Staging Triage (run elevated)
# Checks: shadow copies, scheduled tasks (last 7 days), RDP exposure, suspicious services
$lookback = (Get-Date).AddDays(-7)
Write-Host "=== [1] Volume Shadow Copies ===" -ForegroundColor Cyan
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
if (-not $shadows) { Write-Host "WARNING: No shadow copies present - possible vssadmin deletion" -ForegroundColor Red }
else { $shadows | Select-Object InstallDate, VolumeName | Format-Table }
vssadmin list shadows 2>$null
Write-Host "=== [2] Scheduled Tasks Created in Last 7 Days ===" -ForegroundColor Cyan
Get-ScheduledTask | Where-Object { $_.Date -and ([datetime]$_.Date) -gt $lookback } |
Select-Object TaskName, TaskPath, Date, @{N='Author';E={$_.Author}} | Format-Table -AutoSize
Write-Host "=== [3] RDP Exposure Check ===" -ForegroundColor Cyan
$rdpEnabled = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections).fDenyTSConnections
$nla = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -ErrorAction SilentlyContinue).UserAuthentication
Write-Host "RDP Disabled flag (0 = RDP ENABLED): $rdpEnabled"
Write-Host "NLA Required (1 = yes): $nla"
$rdpListen = Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue
if ($rdpListen) { Write-Host "ALERT: RDP is LISTENING on 3389" -ForegroundColor Red }
Write-Host "=== [4] Recently Installed Services (last 7 days) ===" -ForegroundColor Cyan
Get-WinEvent -FilterHashtable @{LogName='System'; Id=7045; StartTime=$lookback} -ErrorAction SilentlyContinue |
Select-Object TimeCreated, Message | Format-List
Write-Host "=== [5] Cobalt Strike-style Named Pipes ===" -ForegroundColor Cyan
Get-ChildItem \\.\pipe\ -ErrorAction SilentlyContinue | Where-Object {
$_.Name -match '^(msagent_|postex_|status_|mojo\.|[0-9a-f]{4,}$)' } | Select-Object Name
Write-Host "Triage complete. Escalate any red-flag output to IR immediately." -ForegroundColor Green
Incident Response Priorities
T-minus detection checklist (before encryption fires)
If RHYSIDA or a similar actor claims your organization, or the hunt queries above fire, check in this order:
- Shadow copy integrity —
vssadmin delete shadowsorbcdedittampering is the strongest single pre-detonation signal - New services and scheduled tasks — 7045 events and task creation in the last 7 days, especially with random names or
SYSTEMcontext - SMB/ADMIN$ fan-out — one host suddenly touching many others over 445/135
- Outbound volume anomalies — sustained transfers to rare external IPs, cloud storage, or VPS providers (RHYSIDA historically uses off-the-shelf exfil tooling and legitimate cloud services)
- Credential access artifacts — LSASS access by non-standard processes, DCSync-style replication requests
- New VPN/firewall admin sessions — especially outside change windows, matching edge-device exploitation hypotheses
Critical assets this gang historically prioritizes for exfiltration
- HR records, payroll, and employee PII (leverage for pressure)
- Client/constituent data — for government entities, resident records carry regulatory and political weight
- Legal and financial documents — for professional services firms, privileged client files are the highest-value extortion material
- Email archives of executives and finance staff
Containment actions, ordered by urgency
- Isolate, don't reboot — network-isolate affected hosts to preserve volatile evidence while severing C2 and exfil paths
- Disable suspect accounts and force global credential resets — assume domain credential compromise; prioritize service and admin accounts
- Block identified exfil destinations at egress; sinkhole known C2 if observed
- Snapshot/halt exposed edge devices (VPN concentrators, firewalls) pending forensic imaging if exploitation is suspected
- Protect backups — verify offline/immutable copies are actually unreachable from the production domain before attackers find them
- Engage counsel and IR retainer — disclosure obligations vary by sector and state; government entities face additional statutory requirements
Hardening Recommendations
Immediate (24 hours)
- Patch the five KEV CVEs listed above on any exposed instance — vCenter, TeamCity, Cisco FMC, Check Point gateways, and developer tooling are all confirmed ransomware-exploited in 2026
- Enforce phishing-resistant MFA on all remote access (VPN, RDP gateways, webmail). RHYSIDA's documented reliance on valid accounts makes this the single highest-leverage control
- Disable or ACL RDP from the internet entirely; if business-required, gate behind VPN + MFA + NLA
- Audit scheduled tasks and services created in the last 30 days against a known-good baseline (use the script above)
- Verify backup immutability and test one restore today — not this week
Short-term (2 weeks)
- Segment management planes — vCenter, firewall management, and CI/CD infrastructure should sit in dedicated, jump-host-gated segments unreachable from general user VLANs
- Deploy the Sigma rules and KQL hunt above into your SIEM with tuned thresholds; alert on shadow copy tampering at critical severity
- Egress filtering with allowlisting for server VLANs — servers rarely need unrestricted outbound internet; blocking it kneecaps exfil and C2
- LSASS protection and credential guard across the fleet; restrict DCSync-capable permissions to actual DCs
- Tabletop a leak-site scenario — the first public notice of a RHYSIDA intrusion is often the gang's own posting. Your comms, legal, and exec teams should rehearse responding to a claim before one names you
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.