Rhysida Ransomware: What You Need to Know & How to Recover Fast

In February 2024, researchers at Kookmin University and KISA published a free decryptor for Rhysida after finding a flaw in its key generation; the tool covers only the Windows encryptor. Find out where it stops short, what the CriticalBreachDetected note demands, and — if your environment is affected — how our responders restore your systems.

Get Help Now

What is Rhysida Ransomware?

Rhysida runs as a ransomware-as-a-service, leasing tooling to affiliates and splitting each ransom with them. Intrusions lean on living-off-the-land tools such as PowerShell and PsExec, with ntdsutil used to dump the NTDS.dit database from domain controllers. Payloads exist for Windows, PowerShell and Linux/ESXi, appending the .rhysida extension after intermittent encryption. BeforeCrypt can help you contain the attack, assess recovery options and restore operations safely.

Info card image
Data Theft Before Encryption
Rhysida exfiltrates files first, so the leak threat exists independently of your backups.
Info card image
Windows & ESXi Targeting
Affiliates encrypt Windows systems and can also target VMware ESXi hosts, which complicates restoration.
Info card image
Decryption Needs Checking
A free decryptor published in February 2024 covers Rhysida's Windows PE encryptor, and whether it applies to your systems must be verified before use.
Info card image
Active Leak Site Pressure
Stolen data is published or auctioned if talks fail, adding regulatory and reputational risk to the file loss.

Why You Shouldn’t Attempt to Fix It Alone

A free decryptor exists for certain Rhysida variants: researchers at Kookmin University and KISA published one in February 2024, and Avast released its own. Both cover the Windows encryptor, not the ESXi or PowerShell-based variants, and whether either applies has to be verified technically. An unverified or unsuitable tool can make recovery harder, so tools are tested on copies first.

Rhysida exfiltrates data before encrypting it, so this risk stands apart from your backups. Restoring files will not stop stolen records appearing on the leak site, where Rhysida has auctioned data from previous victims. Notification obligations depend on your sector and geography — see the FAQ below for the regulatory clocks that may apply.

BeforeCrypt can run the full response — forensic triage, containment, eradication, recovery — or work alongside your IT team: establishing what was taken, sanctions screening before any payment, evidence preservation for insurers and regulators, coordinating notification timelines, and negotiation to reduce the demand or buy time where that is the right route. Technical response, internal coordination, customer and regulator communication and attacker contact landing at once strains internal teams.

An experienced internal security team can handle substantial parts of the response itself. Our detailed emergency response plan walks through the sequence step by step. A free assessment call helps you decide what stays in-house and where specialist support saves time.

Intro right image

Rhysida drops a PDF ransom note named CriticalBreachDetected.pdf on affected systems, styled to resemble a formal security bulletin rather than a plain text file. It includes a unique victim code and directs victims to the group’s Tor-based negotiation portal.

YOU MUST NOT ATTEMPT TO TOUCH, RESTORE OR OVERWRITE THE DATA.

Steps bg image

Hit by Rhysida Ransomware? Take These Immediate Recovery Steps

If you’ve fallen victim to ransomware, follow these crucial steps:

1

Request 24/7 Ransomware Recovery Help

Get expert guidance to assess, contain, and recover safely.

2

Isolate Infected Systems

Disconnect infected devices to stop the spread. Avoid self-recovery.

3

Preserve Evidence Immediately

Keep ransom notes & logs. Do not restart or modify anything.

Rhysida ransomware statistics & facts

RANSOM SUMMARY

Name Rhysida (possible links to Vice Society)
Danger level Very High. Encrypts files and exfiltrates data, targeting healthcare, education and government sectors.
Release date 2023
OS affected Windows and Linux/VMware ESXi
Appended file extensions .rhysida
Ransom note filename CriticalBreachDetected.pdf
Contact channels Tor-based negotiation portal with unique victim ID (per ransom note)

COMMON ATTACK VECTORS

  • External Remote Services (T1133) — CISA, FBI and MS-ISAC document intrusions through external-facing remote services such as VPNs, including environments without multi-factor authentication.
  • Drive-by Compromise (T1189) — SEO-poisoned fake Microsoft Teams installers signed with fraudulently obtained certificates delivered a loader and the Oyster backdoor before Rhysida deployment (Microsoft, October 2025).
  • Phishing (T1566) — email lures used to deliver initial payloads or harvest credentials.
  • Exploitation for Privilege Escalation (T1068) — including exploitation of the Zerologon vulnerability (CVE-2020-1472) against domain controllers.
  • Remote Services / Lateral Tool Transfer (T1021) — legitimate remote access and administration tools such as AnyDesk, PsExec, RDP (mstsc.exe) and PuTTY used to move through the network.

RANSOM AMOUNTS

US authorities describe Rhysida’s victims as ‘targets of opportunity’, with education, healthcare and government most affected and entry typically through exposed remote services, phishing or trojanised software downloads.

Documented Rhysida demands range from roughly €330,000 claimed from a German city administration in May 2026 to 30 bitcoin (about €2 million) demanded from a German state administration in August 2026, and stolen datasets have been auctioned for as much as 60 bitcoin (about $3.4 million). Ransoms are usually paid in Bitcoin. Quick-buy methods of purchasing Bitcoin with PayPal or credit cards do not work for this size of ransom payment and it is important to obtain expert advice to ensure that a payment of this size is legally compliant.

Our experienced negotiation team has consistently secured meaningful reductions from the initial demand to the final settlement across Rhysida engagements.

AVERAGE LENGTH

Because Rhysida actors dump the NTDS.dit database from domain controllers, CISA advises domain-wide password resets and double Kerberos ticket resets — work that must finish before systems can be trusted again.

For most ransomware victims, downtime is the most costly aspect of the incident, with potential for considerable reputational harm.

Our extensive experience with Rhysida ransomware gives us a deep understanding of the gang’s tactics, enabling us to resolve attacks swiftly and restore your files.

How to identify rhysida ransomware

Rhysida drops its ransom note as a PDF file rather than plain text, formatted to resemble an official security incident notice. It contains a unique victim identifier and points to the group’s Tor negotiation portal.

Text extract: CriticalBreachDetected.pdf
Critical Breach Detected - Immediate Response Required Dear company, This is an automated alert from cybersecurity team Rhysida. An unfortunate situation has arisen - your digital ecosystem has been compromised, and a substantial amount of confidential data has been exfiltrated from your network. The potential ramifications of this could be dire, including the sale, publication, or distribution of your data to competitors or media outlets. This could inflict significant reputational and financial damage. However, this situation is not without a remedy. Our team has developed a unique key, specifically designed to restore your digital security. This key represents the first and most crucial step in recovering from this situation. To utilize this key, visit our secure portal: [redacted] with your secret key [snip] It's vital to note that any attempts to decrypt the encrypted files independently could lead to permanent data loss. We strongly advise against such actions. Time is a critical factor in mitigating the impact of this breach. With each passing moment, the potential damage escalates. Your immediate action and full cooperation are required to navigate this scenario effectively. Rest assured, our team is committed to guiding you through this process. The journey to resolution begins with the use of the unique key. Together, we can restore the security of your digital environment. Best regards

Frequently asked questions

How Does Ransomware Encrypt Files?

Ransomware encrypts files using advanced cryptographic algorithms, typically AES (Advanced Encryption Standard) or RSA (Rivest-Shamir-Adleman). Once executed, the malware scans the system for specific file types and encrypts them, making them inaccessible to the user. Some variants use symmetric encryption (AES), while others combine it with asymmetric encryption (RSA) to lock files with a unique key pair.

Can You Decrypt My Ransomware Encrypted Files?

Decryption depends on the ransomware variant. In some cases, publicly available decryption tools exist, but not all attacks have a known solution. You can submit a free ransomware recovery request, and we will check for possible decryption methods.

Do I have to report a ransomware attack to regulators, and when?

In most cases involving personal data, which applies to nearly every ransomware incident, reporting is legally required. In the EU, GDPR requires notification to the relevant data protection authority within 72 hours of becoming aware of a personal data breach. The UK ICO requires the same 72-hour window. In the US, HIPAA-covered entities have 60 days to notify affected individuals (and immediately for breaches affecting 500+ people). The clock starts from awareness of the incident, not from a full technical understanding.

Is it legal to pay a ransom?

In most jurisdictions, paying a ransom is not illegal in itself — but it can become illegal if the payment ends up going to a sanctioned entity or country (OFAC-designated groups in the US, EU sanctions lists, UK Treasury lists). Before any payment, sanctions screening is essential. BeforeCrypt handles this compliance layer as a standard part of every engagement.

Will paying the ransom actually get my files back?

Most established ransomware groups do provide working decryption tools when paid — the business model depends on their reputation for delivery. However, decryptors are often slow, incomplete, or corrupt a percentage of files during recovery. This is where working with a specialist matters: BeforeCrypt tracks the delivery reliability of specific groups, negotiates sample-file decryption as proof of capability where the group allows it, and plans realistic recovery timelines based on our own engagement history with each group.

What happens if we don't pay the ransom?

Most modern ransomware groups follow through on publication threats — stolen data appears on the group's leak site, is often mirrored to Telegram and dark web forums, and may be sold to third parties. Recovery becomes limited to whatever you can rebuild from backups.

Are our files still at risk if we have working backups?

Backups protect against file loss but not against data theft. Most modern ransomware groups exfiltrate sensitive data BEFORE encryption and threaten to publish it regardless of your recovery capability. This is why leak-site publication and negotiation still matter even for organisations with clean, offline backups — and why "we can just restore from backup" rarely tells the full story.

Should we contact law enforcement after a ransomware attack?

In most jurisdictions, yes — reporting is a standard part of a ransomware incident and, in some cases, legally required. In the US, that means the FBI (via IC3 or a local field office) and CISA. In the EU, national CERT and cybercrime units. Reporting does not obligate you to any specific recovery path but does open access to threat intelligence and, occasionally, decryption tools recovered by law enforcement.

Do you have deep experience with ransomware incidents?

Yes. We’ve handled 1,700+ incidents across ransomware, BEC and data-leak extortion. We identify the variant, decide decrypt vs. clean verified restore, and guide a controlled return to operations. When needed, we support negotiation & compliance—always legally and with a clear audit trail.

Will insurers accept your findings and reports?

Yes. We produce insurer-ready incident reports with a defensible timeline, scope, likely entry path, exfiltration assessment, actions taken, and chain-of-custody. We can join the adjuster call, map our findings to your carrier’s forms, and provide GDPR/NIS2 notifications where required. Final acceptance always depends on the policy and carrier, but our packages are designed to speed up approvals and reduce back-and-forth.

How is this different from my MSP or the insurer’s hotline?

MSPs keep IT running; they’re not built for evidence handling and incident triage. Insurer panels optimize claims, not necessarily speed & clarity for your business. We work alongside both: kick off in ≤2h, run forensic triage with chain-of-custody, coordinate safe containment, and deliver executive- and insurer-ready findings—without taking your environment hostage.

Why Should I Use A Cyber Incident Service?

Because it turns chaos into fast, safe recovery. We cut downtime and limit damage while preserving evidence. Within ≤48h you get a forensic triage pack (timeline, likely entry path, scope, decrypt-vs-clean-restore decision, go-live criteria) so leadership can act with confidence. Result: controlled, verified restart—not guesswork.