s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.rhysida

📛 Threat Title

Malware family: Rhysida

Category: Rhysida First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.rhysida`. Printable name: Rhysida.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.rhysida VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.rhysida

IOC database

Type
domain
Value
elf.rhysida
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.rhysida

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.rhysida

References (1)

Remediations (10)

  • web:assets.recordedfuture.com

    Rhysida has been observed using a range of tactics to gain initial access, making it generally difficult to pinpoint its primary method. Initial access tactics commonly associated with Rhysida are phishing and the use of valid credentials to access internal VPN access points, often because organizations do not have multi-factor authentication ...

  • web:bazaar.abuse.ch

    Malware samples associated with tag Rhysida MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with Rhysida . Database Entry

  • web:dailysecurityreview.com

    The Rhysida ransomware group—previously known as Vice Society—is exploiting trust in Microsoft platforms to spread malware through deceptive advertisements. In a newly discovered campaign, the gang is targeting users of Microsoft Teams, Zoom, and PuTTY by buying malicious Bing search ads that redirect unsuspecting victims to fraudulent download pages. Once users click the prominent ...

  • web:purple-ops.io

    Microsoft and law enforcement successfully dismantled Fox Tempest, a major malware -signing service used by Rhysida and other ransomware groups.

  • web:tech.yahoo.com

    Experts at Expel spotted a new malware distribution campaign conducted by the Rhysida ransomware group which apparently began in June 2025, and is still ongoing at press time. For the campaign, Rhysida's operatives created landing pages to imitate download sites for Microsoft Teams, one of the world's most popular online collaboration ...

  • web:www.aha.org

    Rhysida—an emerging ransomware variant—has predominately been deployed against the education, healthcare, manufacturing, information technology, and government sectors since May 2023. The information in this CSA is derived from related incident response investigations and malware analysis of samples discovered on victim networks.

  • web:www.blackfog.com

    Rhysida ransomware is escalating U.S. attacks in 2025. See breaches, tactics and a CISA-aligned mitigation guide.

  • web:www.cisa.gov

    Rhysida has predominately been deployed against the education, healthcare, manufacturing, information technology, and government sectors since May 2023. The information in this advisory is derived from related incident response investigations and malware analysis of samples discovered on victim networks.

  • web:www.fortinet.com

    This article provided details of a Rhysida ransomware intrusion investigated by the FortiGuard team. The majority of the TTPs employed by the threat actor during this intrusion are typical for these types of ransomware intrusions, and no novel techniques were observed.

  • web:www.sentinelone.com

    Rhysida is a business ransomware-as-a-service attack that encrypts files and exfiltrates data for double extortion. The attackers deliver the ransom notice to victims through email and dark websites.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.