Classification: TLP:CLEAR | Published: 2026-09-12 | Source: Live monitoring of RHYSIDA .onion leak site via ransomware.live | Analyst: Security Arsenal Threat Intelligence
Executive Summary
Security Arsenal's dark web collection infrastructure has confirmed 4 new victim postings to the RHYSIDA ransomware gang's Tor-based leak site between 2026-09-07 and 2026-09-10. The victims span healthcare, retail & e-commerce, and professional services across the Philippines, France, and the United States — a geographic and sectoral dispersion consistent with RHYSIDA's opportunistic-but-healthcare-leaning targeting doctrine.
The posting cadence (4 victims in ~6 days, including a same-day double-post on 2026-09-10) indicates an active escalation window. Organizations running VMware vCenter, Cisco Secure FMC, Check Point gateways, or ConnectWise ScreenConnect should treat this briefing as an immediate patching and threat-hunting trigger: five CVEs with confirmed ransomware use were added to the CISA KEV in the last four months, and RHYSIDA has historically favored edge-device and remote-access exploitation for initial access.
1. Threat Actor Profile — RHYSIDA
| Attribute | Assessment |
|---|---|
| Known Aliases | Rhysida, Rhysida-0.1 (early ransomware build naming) |
| First Observed | May 2023 |
| Operational Model | Closed/semi-closed group — believed to operate as a private crew rather than a broad RaaS affiliate program, though occasional affiliate-style overlap with Vice Society tooling has been reported |
| Affiliation Links | Code overlap and victimology correlation with Vice Society; assessed likely origin from former Vice Society operators |
| Ransom Demands | Historically $100K–$3M+, scaled to victim revenue; healthcare and public-sector victims see demands in the low-to-mid six figures with pressure via data leak countdowns |
| Extortion Model | Double extortion — encryption + data theft with publication of "proof packs" (PII, passports, financial records) on their .onion site, typically 7–14 days after initial victim listing if payment is not received |
| Initial Access Vectors | (1) Phishing with malicious attachments/links delivering loaders, (2) exploitation of externally-facing VPN/firewall appliances, (3) compromised RDP credentials, (4) abuse of remote management tools (ScreenConnect-class RMM), (5) valid accounts purchased from access brokers |
| Post-Access Tooling | Cobalt Strike beacons, PsExec, WMI for lateral movement; ntdsutil/registry hives for credential theft; vssadmin delete shadows prior to detonation; PowerShell-based staging scripts |
| Average Dwell Time | 4–11 days from initial access to encryption — shorter than the ransomware ecosystem median, meaning pre-detonation detection windows are narrow |
| Notable Prior Campaigns | British Library (Oct 2023), multiple US hospital systems, Chilean Army (Ejército de Chile), Prospect Medical Holdings — healthcare and public sector remain their signature targets |
Analyst Note: RHYSIDA's dwell time is the critical defensive variable. Their operators move from access → credential theft → exfil → encryption in under two weeks, and in some intrusions under 96 hours. Detection content below is optimized for that compressed kill chain.
2. Current Campaign Analysis
Confirmed Leak Site Postings (Live Data)
| Victim | Sector | Country | Published |
|---|---|---|---|
| General Santos Doctors Hospital | Healthcare | PH | 2026-09-10 |
| Professional Retail Services | Retail & E-Commerce | Undisclosed | 2026-09-10 |
| SAD'S Interim | Professional Services (Staffing) | FR | 2026-09-08 |
| Rug & Home | Retail & E-Commerce | US | 2026-09-07 |
Sector Targeting Assessment
- Healthcare (1/4): The General Santos Doctors Hospital posting is the highest-severity victim in this batch. RHYSIDA has an established track record of targeting hospitals and exfiltrating patient PII/PHI as leak leverage. Philippine healthcare infrastructure is historically under-hardened against ransomware, suggesting deliberate target selection rather than pure opportunism.
- Retail & E-Commerce (2/4): Two retail victims in four days. Retail targets typically yield payment card-adjacent data, customer PII, and ERP/financial records. Retail orgs with seasonal staffing often run flat networks and unmanaged RMM tooling — a known RHYSIDA entry point.
- Professional Services (1/4): SAD'S Interim is a French staffing/interim agency. Staffing firms hold dense PII stores (identity documents, payroll, banking details) — high-value leak material with strong GDPR extortion leverage.
Geographic Concentration
No single-country concentration: PH, FR, US plus one undisclosed. This is consistent with RHYSIDA's access-vector-driven (not geography-driven) targeting — they hit whoever has the exposed edge service or phishable user. However, the French posting continues a pattern of EU victims selected partly for GDPR regulatory pressure, which increases extortion leverage.
Victim Profile
Based on sector and public revenue data, this batch skews toward small-to-mid-market organizations (est. $5M–$150M annual revenue, 100–2,500 employees) — the ransomware ecosystem's sweet spot: large enough to pay six-to-seven-figure ransoms, small enough to lack 24/7 SOC coverage. RHYSIDA deliberately avoids the "too big to quietly pay" tier (which invites law-enforcement attention) and the "too small to pay" tier.
Posting Frequency / Escalation Pattern
- 4 postings in 6 days, with a double-post on 2026-09-10 — batching multiple victims on one day is typically a pressure tactic when initial ransom negotiations stall.
- Expect a data-leak escalation wave for these victims approximately 7–14 days post-listing (i.e., 2026-09-14 through 2026-09-24) if ransoms are unpaid. Monitor the leak site for proof-pack drops.
- Low recent posting volume (4 of last 100 tracked postings) relative to peak RHYSIDA activity suggests either a rebuilding phase after operational disruption or intentional low-profile pacing. Either way: the group is active, detonating, and posting now.
Initial Access Vector Correlation — KEV CVEs
While we cannot attribute specific intrusions to specific CVEs from leak-site data alone, the following CISA KEV entries with confirmed ransomware use align directly with RHYSIDA's documented access tradecraft and should be treated as candidate vectors in any related IR:
| CVE | Product | KEV Added | RHYSIDA Relevance |
|---|---|---|---|
| CVE-2026-59310 | Broadcom VMware vCenter (Path Traversal) | 2026-08-18 | Hypervisor compromise enables mass encryption of all hosted VMs — the highest-impact ransomware vector. Patch immediately. |
| CVE-2026-20316 | Cisco Secure FMC (Hard-coded Password) | 2026-07-29 | Firewall management plane takeover → edge access, policy tampering, VPN credential harvesting. Matches RHYSIDA's edge-device preference. |
| CVE-2026-50751 | Check Point Security Gateway (Improper Auth, IKEv1) | 2026-06-08 | VPN gateway auth bypass → direct internal network access. Classic RHYSIDA entry path. |
| CVE-2026-48027 | Nx Console (Embedded Malicious Code) | 2026-05-27 | Supply-chain/developer-workstation vector → credential theft from dev environments, CI/CD pivoting. |
| CVE-2024-1708 | ConnectWise ScreenConnect (Path Traversal → RCE) | 2026-04-28 | RMM exploitation → immediate hands-on-keyboard access. RMM abuse is a documented RHYSIDA/Vice Society hallmark. |
Action: If any of these products are internet-facing in your environment and unpatched, assume exposure and begin hunting with the detections below — do not wait for encryption.
3. Detection Engineering
The following Sigma rules target RHYSIDA's documented TTPs across initial access, lateral movement, and pre-encryption staging. Deploy to your SIEM and tune falsepositive fields to your environment.
---
title: RHYSIDA - Pre-Encryption Defense Evasion via Shadow Copy and Backup Deletion
id: 8f3a2b1c-rhys-0001-9a1e-000000000001
status: experimental
description: Detects Volume Shadow Copy deletion, backup catalog deletion, and boot status tampering consistent with RHYSIDA pre-encryption staging. RHYSIDA operators routinely execute vssadmin/wmic/bcdedit commands within hours of detonation.
author: Security Arsenal Threat Intelligence
date: 2026/09/12
references:
- https://securityarsenal.com/darkside
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-319a
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\vssadmin.exe'
- '\wbadmin.exe'
- '\bcdedit.exe'
- '\wmic.exe'
selection_cmd:
CommandLine|contains:
- 'delete shadows'
- 'shadowcopy delete'
- 'delete catalog'
- 'recoveryenabled no'
- 'bootstatuspolicy ignoreallfailures'
condition: selection_img and selection_cmd
falsepositives:
- Legitimate backup maintenance windows (allowlist by account and host)
- IT administration scripts
level: critical
tags:
- attack.impact
- attack.t1490
---
title: RHYSIDA - Lateral Movement via PsExec or WMI Remote Process Execution
id: 8f3a2b1c-rhys-0002-9a1e-000000000002
status: experimental
description: Detects PsExec service installation and WMI remote process creation patterns used by RHYSIDA for lateral movement and ransomware payload distribution across domain hosts.
author: Security Arsenal Threat Intelligence
date: 2026/09/12
references:
- https://securityarsenal.com/darkside
logsource:
product: windows
service: security
detection:
selection_psexec:
EventID: 7045
ServiceName|contains:
- 'PSEXESVC'
- 'PAExec'
selection_wmi:
EventID: 4688
NewProcessName|endswith: '\WmiPrvSE.exe'
CommandLine|contains:
- 'powershell'
- 'cmd.exe'
- '.bat'
- '.ps1'
condition: selection_psexec or selection_wmi
falsepositives:
- Legitimate admin tooling (SCCM, PDQ Deploy) - allowlist known management servers by SourceComputerName
level: high
tags:
- attack.lateral-movement
- attack.t1021.002
- attack.t1047
- attack.t1569.002
---
title: RHYSIDA - Credential Access via NTDS.dit or Registry Hive Theft
id: 8f3a2b1c-rhys-0003-9a1e-000000000003
status: experimental
description: Detects ntdsutil abuse for Active Directory database extraction and registry hive export of SAM/SYSTEM/SECURITY - a documented RHYSIDA credential theft step preceding lateral movement and exfiltration.
author: Security Arsenal Threat Intelligence
date: 2026/09/12
references:
- https://securityarsenal.com/darkside
logsource:
category: process_creation
product: windows
detection:
selection_ntds:
Image|endswith: '\ntdsutil.exe'
CommandLine|contains:
- 'activate instance ntds'
- 'ifm'
- 'create full'
selection_reg:
Image|endswith:
- '\reg.exe'
- '\cmd.exe'
- '\powershell.exe'
CommandLine|contains:
- 'save HKLM\SAM'
- 'save HKLM\SYSTEM'
- 'save HKLM\SECURITY'
- 'save hklm\sam'
- 'save hklm\system'
- 'save hklm\security'
condition: selection_ntds or selection_reg
falsepositives:
- DC maintenance by domain admins (allowlist by user and maintenance window)
level: critical
tags:
- attack.credential-access
- attack.t1003.003
- attack.t1003.002
Microsoft Sentinel — KQL Hunt: Pre-Ransomware Staging & Lateral Movement Chain
This hunt correlates credential theft → remote execution → shadow copy deletion within a 6-hour sliding window per host, matching RHYSIDA's compressed kill chain. Run over the last 14 days.
let lookback = 14d;
let window = 6h;
let CredTheft = materialize(
SecurityEvent
| where TimeGenerated > ago(lookback)
| where EventID == 4688
| where CommandLine has_any ("ntdsutil", "save HKLM\\SAM", "save hklm\\sam", "vssadmin delete shadows", "wbadmin delete catalog")
| project CredTime = TimeGenerated, Computer, Account, CredCmd = CommandLine
);
let RemoteExec = materialize(
SecurityEvent
| where TimeGenerated > ago(lookback)
| where (EventID == 7045 and ServiceName has "PSEXESVC")
or (EventID == 4688 and Process has "WmiPrvSE.exe")
| project ExecTime = TimeGenerated, Computer, ExecEvent = EventID, ExecCmd = CommandLine
);
let SuspiciousArchive = materialize(
DeviceProcessEvents
| where TimeGenerated > ago(lookback)
| where ProcessCommandLine has_any ("rar.exe", "7z.exe", "7za.exe", "a ", " -p")
and ProcessCommandLine has_any ("\\users\\", "\\documents\\", "\\shares\\", "recurse")
| project ArchiveTime = TimeGenerated, DeviceName, ArchiveCmd = ProcessCommandLine, InitiatingProcessAccountName
);
CredTheft
| join kind=inner (RemoteExec) on Computer
| where ExecTime between (CredTime .. CredTime + window)
| join kind=leftouter (SuspiciousArchive) on $left.Computer == $right.DeviceName
| summarize
FirstSeen = min(CredTime),
LastSeen = max(ExecTime),
CredentialTheftCmds = make_set(CredCmd),
RemoteExecCmds = make_set(ExecCmd),
StagingCmds = make_set(ArchiveCmd)
by Computer, Account
| extend RHYSIDA_ChainScore = iff(array_length(StagingCmds) > 0, 3, 2)
| sort by RHYSIDA_ChainScore desc, FirstSeen asc
Rapid Response Script — Exposed RDP + Recent Scheduled Tasks + Shadow Copy Integrity
Run this PowerShell triage script (as admin) on any host suspected of RHYSIDA pre-detonation activity. It checks the three highest-signal indicators in one pass.
#Requires -RunAsAdministrator
# Security Arsenal - RHYSIDA Rapid Triage Script (2026-09-12)
# Checks: exposed RDP listeners, scheduled tasks created in last 7 days, VSS integrity
Write-Host "=== [1/4] RDP Exposure Check ===" -ForegroundColor Cyan
$rdpEnabled = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server').fDenyTSConnections -eq 0
$rdpListening = Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue
if ($rdpEnabled -and $rdpListening) {
Write-Host "[!] RDP ENABLED AND LISTENING on 3389" -ForegroundColor Red
$nla = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp').UserAuthentication
if ($nla -ne 1) { Write-Host "[!!] NLA DISABLED - brute-forceable RDP" -ForegroundColor Red }
} else { Write-Host "[OK] RDP not listening" -ForegroundColor Green }
Write-Host "=== [2/4] Scheduled Tasks Created in Last 7 Days ===" -ForegroundColor Cyan
Get-ScheduledTask | Where-Object { $_.Date -and ([datetime]$_.Date) -gt (Get-Date).AddDays(-7) } |
Select-Object TaskName, TaskPath, Date, @{N='Action';E={$_.Actions.Execute + ' ' + $_.Actions.Arguments}} |
Format-Table -AutoSize | Out-String | Write-Host
Write-Host "=== [3/4] Volume Shadow Copy Integrity ===" -ForegroundColor Cyan
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
if (-not $shadows) {
Write-Host "[!!] NO SHADOW COPIES FOUND - possible pre-encryption deletion (T1490)" -ForegroundColor Red
} else {
Write-Host "[OK] $($shadows.Count) shadow copies present. Newest: $(($shadows | Sort-Object InstallDate -Descending | Select-Object -First 1).InstallDate)" -ForegroundColor Green
}
Write-Host "=== [4/4] Recent 4625 Failed Logons (brute force signal, last 24h) ===" -ForegroundColor Cyan
$fails = Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=(Get-Date).AddDays(-1)} -ErrorAction SilentlyContinue
if ($fails.Count -gt 100) {
Write-Host "[!] $($fails.Count) failed logons in 24h - investigate source IPs/accounts" -ForegroundColor Red
$fails | Group-Object { $_.Properties[19].Value } | Sort-Object Count -Descending | Select-Object -First 5 Name, Count | Format-Table -AutoSize | Out-String | Write-Host
} else { Write-Host "[OK] Failed logon volume normal ($($fails.Count))" -ForegroundColor Green }
Write-Host "=== Triage Complete - escalate to IR if any [!] or [!!] flags fired ===" -ForegroundColor Cyan
4. Incident Response Priorities
T-Minus Detection Checklist (Before Encryption Fires)
Given RHYSIDA's 4–11 day dwell time, hunt for these in sequence — any two together warrant full IR activation:
- Edge device anomalies — new admin sessions or config exports on VPN/firewall appliances (Check Point, Cisco FMC) outside change windows
- Credential theft artifacts —
ntdsutil ifmexecution,reg save HKLM\SAM, suspicious LSASS access (Event 4663/10) - Cobalt Strike indicators — named pipes matching
\\.\pipe\msagent_*/\\.\pipe\postex_*, Malleable C2 beaconing to low-reputation HTTPS endpoints - Staging behavior — mass 7z/RAR archive creation in user directories or file shares, especially password-protected archives
- Exfil signals — sustained outbound transfers to cloud storage (MEGA, Dropbox, file.io) or unknown VPS endpoints from servers that don't normally egress
- Pre-detonation kill shots —
vssadmin delete shadows,bcdedit ... recoveryenabled no, mass AV/EDR service stop attempts, new PsExec services on multiple hosts within minutes
Critical Assets RHYSIDA Prioritizes for Exfiltration
- Patient/medical records (PHI) — primary leverage in healthcare intrusions (see: General Santos Doctors Hospital)
- HR & identity documents — passports, payroll, banking details (especially from staffing/professional services victims)
- Customer PII databases — retail CRM/e-commerce backends
- Financial records & contracts — used to calibrate ransom demands
- Email archives of executives/legal — for secondary extortion threads
Containment Actions (Ordered by Urgency)
- (0–15 min) Isolate affected hosts/segments at the switch/EDR level — do NOT power off (preserve memory for forensics); block known Cobalt Strike C2 at egress
- (15–60 min) Disable compromised accounts; force enterprise-wide credential reset starting with Domain Admins, service accounts, and VPN users; revoke active sessions/tokens
- (1–4h) Block egress to attacker exfil infrastructure; snapshot/quarantine file servers; verify backup integrity and take backups offline
- (4–24h) Patch/close the ingress vector (KEV CVEs above); deploy detection rules from Section 3 environment-wide; sweep for persistence (scheduled tasks, new local admins, rogue RMM agents)
- (24h+) Engage external IR if encryption or exfil confirmed; assess notification obligations (HIPAA for PHI, GDPR for EU data, state breach laws for US PII)
5. Hardening Recommendations
Immediate (Next 24 Hours)
- Patch the five KEV CVEs listed in Section 2 on any internet-facing or management-plane instance — vCenter (CVE-2026-59310) and ScreenConnect (CVE-2024-1708) first
- Enforce MFA on all VPN and remote access; disable IKEv1 on Check Point gateways where unused (directly mitigates CVE-2026-50751 class attacks)
- Disable or restrict RDP — NLA required, no direct internet exposure, RD Gateway or ZTNA only
- Block
vssadmin delete shadowsandbcdedittampering via AppLocker/WDAC for non-admin contexts, and alert on any execution (rules above) - Audit for unauthorized RMM tools (ScreenConnect, AnyDesk, etc.) — block execution of unapproved remote access binaries
- Deploy the Sigma rules and KQL hunt above; run the triage script on domain controllers, file servers, and backup infrastructure
Short-Term (2 Weeks)
- Segment the network — isolate backup infrastructure, hypervisor management (vCenter), and medical/clinical VLANs from general user subnets; ransomware dies without lateral paths
- Deploy EDR with tamper protection on all servers including domain controllers; ensure isolation capability is tested
- Implement phishing-resistant MFA (FIDO2) for admins and remote workers; retire legacy email-auth VPN paths
- Immutable/offline backups with tested restoration runbooks — RHYSIDA actively hunts connected backup infrastructure
- Restrict PsExec/WMI lateral movement — disable admin$ where feasible, enforce LAPS, tier administrative access
- Egress filtering + DLP on file servers and database hosts to catch staging/exfil before detonation
- Tabletop the 4-day dwell scenario — your IR plan must function on a weekend timeline with skeleton staff, because that is exactly when RHYSIDA detonates
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.