TF-MAL-elf.rhysida
📛 Threat Title
Malware family: Rhysida
Description
ThreatFox malware family `elf.rhysida`. Printable name: Rhysida.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.rhysida
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.rhysida
IOC database
- Type
- domain
- Value
elf.rhysida- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.rhysida
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.rhysida
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:assets.recordedfuture.com
Rhysida has been observed using a range of tactics to gain initial access, making it generally difficult to pinpoint its primary method. Initial access tactics commonly associated with Rhysida are phishing and the use of valid credentials to access internal VPN access points, often because organizations do not have multi-factor authentication ...
-
web:bazaar.abuse.ch
Malware samples associated with tag Rhysida MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with Rhysida . Database Entry
-
web:dailysecurityreview.com
The Rhysida ransomware group—previously known as Vice Society—is exploiting trust in Microsoft platforms to spread malware through deceptive advertisements. In a newly discovered campaign, the gang is targeting users of Microsoft Teams, Zoom, and PuTTY by buying malicious Bing search ads that redirect unsuspecting victims to fraudulent download pages. Once users click the prominent ...
-
web:purple-ops.io
Microsoft and law enforcement successfully dismantled Fox Tempest, a major malware -signing service used by Rhysida and other ransomware groups.
-
web:tech.yahoo.com
Experts at Expel spotted a new malware distribution campaign conducted by the Rhysida ransomware group which apparently began in June 2025, and is still ongoing at press time. For the campaign, Rhysida's operatives created landing pages to imitate download sites for Microsoft Teams, one of the world's most popular online collaboration ...
-
web:www.aha.org
Rhysida—an emerging ransomware variant—has predominately been deployed against the education, healthcare, manufacturing, information technology, and government sectors since May 2023. The information in this CSA is derived from related incident response investigations and malware analysis of samples discovered on victim networks.
-
web:www.blackfog.com
Rhysida ransomware is escalating U.S. attacks in 2025. See breaches, tactics and a CISA-aligned mitigation guide.
-
web:www.cisa.gov
Rhysida has predominately been deployed against the education, healthcare, manufacturing, information technology, and government sectors since May 2023. The information in this advisory is derived from related incident response investigations and malware analysis of samples discovered on victim networks.
-
web:www.fortinet.com
This article provided details of a Rhysida ransomware intrusion investigated by the FortiGuard team. The majority of the TTPs employed by the threat actor during this intrusion are typical for these types of ransomware intrusions, and no novel techniques were observed.
-
web:www.sentinelone.com
Rhysida is a business ransomware-as-a-service attack that encrypts files and exfiltrates data for double extortion. The attackers deliver the ransom notice to victims through email and dark websites.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.