Rhysida Ransomware — Victims, Campaigns & Activity

Threat entity extracted from intelligence sources

Frequency
39
occurrences
First Seen
October 31, 2025
Last Seen
June 25, 2026

Rhysida is a ransomware_group tracked across 19 threat clusters and 39 intelligence report mentions on ThreatCluster. First observed October 31, 2025; most recent activity June 25, 2026.

Related Threat Clusters

  • Microsoft Disrupts Fox Tempest Malware-Signing Service for Ransomware Gangs

    On May 19, 2026, Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) operation that provided over 1,000 fraudulent code-signing certificates to cybercriminals, enabling them to disguise malware as…

    33 articles · Updated May 19, 2026
  • New Mistic Backdoor Linked to Ransomware Access Broker Activity

    A new backdoor known as Mistic has been identified in cyberattacks targeting various sectors since April 2026. It is associated with the initial access broker KongTuke, also known as Woodgnat, which sells access to…

    21 articles · Updated June 24, 2026
  • Cookeville Medical Center Data Breach Affects Over 337,000 Patients

    Cookeville Regional Medical Center (CRMC) in Tennessee reported a ransomware attack that compromised the personal and medical data of 337,917 patients. The attack occurred between July 11 and July 14, 2025, and was…

    5 articles · Updated April 16, 2026
  • Ransomware Fuels Surge in Global Cyberattacks

    As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…

    1551 articles · Updated February 12, 2026
  • Rise of AI-Driven Scams Targeting UK SMEs

    UK small and medium-sized enterprises (SMEs) are increasingly vulnerable to sophisticated AI-driven scams, as highlighted by recent reports. The emergence of 'AI scams 2.0' combines traditional social engineering…

    742 articles · Updated March 12, 2026
  • Gootloader Malware Resurgence Leads to Domain Controller Compromise

    Recent Gootloader attacks have resulted in a Domain Controller compromise within 17 hours, as reported by Huntress. The Gootloader malware, which has been active since 2020, was previously inactive but saw a resurgence…

    2 articles · Updated November 6, 2025
  • UK Museums Vulnerable to Cyber Threats and Theft, MPs Warn

    The Public Accounts Committee (PAC) has reported that UK national museums and galleries are highly vulnerable to cyber threats and theft, following significant incidents like the British Library ransomware attack and…

    6 articles · Updated June 24, 2026
  • Rhysida and Interlock Ransomware Groups Exploit Shared Malware Ecosystem

    Recent analysis reveals that Rhysida and Interlock ransomware groups are interconnected through a shared ecosystem of malware tools, including the Supper backdoor. Both groups utilize initial access brokers and a…

    3 articles · Updated June 16, 2026
  • SUCCESS Magazine Subscriber Data Leaked on Hacker Forum

    A dataset containing subscriber information from SUCCESS Magazine has reportedly been leaked on a hacker forum. The data includes full names, physical and email addresses, phone numbers, and subscription details. This…

    2 articles · Updated March 11, 2026
  • Oyster Backdoor Malware Spread via Fake Downloads Targeting Financial Sector

    Cybercriminals are distributing the Oyster backdoor malware disguised as popular office tools, including Microsoft Teams and Google Meet. This campaign, targeting individuals in the financial sector, has been active…

    1 article · Updated December 15, 2025

Recent Intelligence Reports

  • Stealthy Mistic Backdoor Targets Enterprise Networks via KongTuke Ransomware Access Broker — Rescana · June 25, 2026
  • Be on the lookout for Mistic, a new backdoor used by ransomware broker — Csoonline · June 24, 2026
  • Symantec’s Threat Hunter Team observed ModeloRAT — www.security.com · June 24, 2026
  • Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker — Security · June 24, 2026
  • ModeloRAT and Mistic Backdoor Activity Linked to Ransomware Initial Access Broker — Gbhackers · June 24, 2026
  • UK’s cultural institutions failing on cyber security, warns PAC — Computerweekly · June 24, 2026
  • Stealthy Mistic backdoor linked to ransomware access broker KongTuke — Bleepingcomputer · June 24, 2026
  • Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker — Security · June 24, 2026

CVSS v3.1 Breakdown