Rhysida Ransomware: What You Need to Know & How to Recover Fast
In February 2024, researchers at Kookmin University and KISA published a free decryptor for Rhysida after finding a flaw in its key generation; the tool covers only the Windows encryptor. Find out where it stops short, what the CriticalBreachDetected note demands, and — if your environment is affected — how our responders restore your systems.
What is Rhysida Ransomware?
Rhysida runs as a ransomware-as-a-service, leasing tooling to affiliates and splitting each ransom with them. Intrusions lean on living-off-the-land tools such as PowerShell and PsExec, with ntdsutil used to dump the NTDS.dit database from domain controllers. Payloads exist for Windows, PowerShell and Linux/ESXi, appending the .rhysida extension after intermittent encryption. BeforeCrypt can help you contain the attack, assess recovery options and restore operations safely.
Data Theft Before Encryption
Rhysida exfiltrates files first, so the leak threat exists independently of your backups.Windows & ESXi Targeting
Affiliates encrypt Windows systems and can also target VMware ESXi hosts, which complicates restoration.Decryption Needs Checking
A free decryptor published in February 2024 covers Rhysida's Windows PE encryptor, and whether it applies to your systems must be verified before use.Active Leak Site Pressure
Stolen data is published or auctioned if talks fail, adding regulatory and reputational risk to the file loss.Why You Shouldn’t Attempt to Fix It Alone
A free decryptor exists for certain Rhysida variants: researchers at Kookmin University and KISA published one in February 2024, and Avast released its own. Both cover the Windows encryptor, not the ESXi or PowerShell-based variants, and whether either applies has to be verified technically. An unverified or unsuitable tool can make recovery harder, so tools are tested on copies first.
Rhysida exfiltrates data before encrypting it, so this risk stands apart from your backups. Restoring files will not stop stolen records appearing on the leak site, where Rhysida has auctioned data from previous victims. Notification obligations depend on your sector and geography — see the FAQ below for the regulatory clocks that may apply.
BeforeCrypt can run the full response — forensic triage, containment, eradication, recovery — or work alongside your IT team: establishing what was taken, sanctions screening before any payment, evidence preservation for insurers and regulators, coordinating notification timelines, and negotiation to reduce the demand or buy time where that is the right route. Technical response, internal coordination, customer and regulator communication and attacker contact landing at once strains internal teams.
An experienced internal security team can handle substantial parts of the response itself. Our detailed emergency response plan walks through the sequence step by step. A free assessment call helps you decide what stays in-house and where specialist support saves time.
Rhysida drops a PDF ransom note named CriticalBreachDetected.pdf on affected systems, styled to resemble a formal security bulletin rather than a plain text file. It includes a unique victim code and directs victims to the group’s Tor-based negotiation portal.
YOU MUST NOT ATTEMPT TO TOUCH, RESTORE OR OVERWRITE THE DATA.
Hit by Rhysida Ransomware? Take These Immediate Recovery Steps
If you’ve fallen victim to ransomware, follow these crucial steps:
Request 24/7 Ransomware Recovery Help
Get expert guidance to assess, contain, and recover safely.
Isolate Infected Systems
Disconnect infected devices to stop the spread. Avoid self-recovery.
Preserve Evidence Immediately
Keep ransom notes & logs. Do not restart or modify anything.
Rhysida ransomware statistics & facts
RANSOM SUMMARY
| Name | Rhysida (possible links to Vice Society) |
| Danger level | Very High. Encrypts files and exfiltrates data, targeting healthcare, education and government sectors. |
| Release date | 2023 |
| OS affected | Windows and Linux/VMware ESXi |
| Appended file extensions | .rhysida |
| Ransom note filename | CriticalBreachDetected.pdf |
| Contact channels | Tor-based negotiation portal with unique victim ID (per ransom note) |
COMMON ATTACK VECTORS
- External Remote Services (T1133) — CISA, FBI and MS-ISAC document intrusions through external-facing remote services such as VPNs, including environments without multi-factor authentication.
- Drive-by Compromise (T1189) — SEO-poisoned fake Microsoft Teams installers signed with fraudulently obtained certificates delivered a loader and the Oyster backdoor before Rhysida deployment (Microsoft, October 2025).
- Phishing (T1566) — email lures used to deliver initial payloads or harvest credentials.
- Exploitation for Privilege Escalation (T1068) — including exploitation of the Zerologon vulnerability (CVE-2020-1472) against domain controllers.
- Remote Services / Lateral Tool Transfer (T1021) — legitimate remote access and administration tools such as AnyDesk, PsExec, RDP (mstsc.exe) and PuTTY used to move through the network.
RANSOM AMOUNTS
US authorities describe Rhysida’s victims as ‘targets of opportunity’, with education, healthcare and government most affected and entry typically through exposed remote services, phishing or trojanised software downloads.
Documented Rhysida demands range from roughly €330,000 claimed from a German city administration in May 2026 to 30 bitcoin (about €2 million) demanded from a German state administration in August 2026, and stolen datasets have been auctioned for as much as 60 bitcoin (about $3.4 million). Ransoms are usually paid in Bitcoin. Quick-buy methods of purchasing Bitcoin with PayPal or credit cards do not work for this size of ransom payment and it is important to obtain expert advice to ensure that a payment of this size is legally compliant.
Our experienced negotiation team has consistently secured meaningful reductions from the initial demand to the final settlement across Rhysida engagements.
AVERAGE LENGTH
Because Rhysida actors dump the NTDS.dit database from domain controllers, CISA advises domain-wide password resets and double Kerberos ticket resets — work that must finish before systems can be trusted again.
For most ransomware victims, downtime is the most costly aspect of the incident, with potential for considerable reputational harm.
Our extensive experience with Rhysida ransomware gives us a deep understanding of the gang’s tactics, enabling us to resolve attacks swiftly and restore your files.
How to identify rhysida ransomware
Rhysida drops its ransom note as a PDF file rather than plain text, formatted to resemble an official security incident notice. It contains a unique victim identifier and points to the group’s Tor negotiation portal.
Frequently asked questions
Decryption depends on the ransomware variant. In some cases, publicly available decryption tools exist, but not all attacks have a known solution. You can submit a free ransomware recovery request, and we will check for possible decryption methods.
In most cases involving personal data, which applies to nearly every ransomware incident, reporting is legally required. In the EU, GDPR requires notification to the relevant data protection authority within 72 hours of becoming aware of a personal data breach. The UK ICO requires the same 72-hour window. In the US, HIPAA-covered entities have 60 days to notify affected individuals (and immediately for breaches affecting 500+ people). The clock starts from awareness of the incident, not from a full technical understanding.
In most jurisdictions, paying a ransom is not illegal in itself — but it can become illegal if the payment ends up going to a sanctioned entity or country (OFAC-designated groups in the US, EU sanctions lists, UK Treasury lists). Before any payment, sanctions screening is essential. BeforeCrypt handles this compliance layer as a standard part of every engagement.
Most established ransomware groups do provide working decryption tools when paid — the business model depends on their reputation for delivery. However, decryptors are often slow, incomplete, or corrupt a percentage of files during recovery. This is where working with a specialist matters: BeforeCrypt tracks the delivery reliability of specific groups, negotiates sample-file decryption as proof of capability where the group allows it, and plans realistic recovery timelines based on our own engagement history with each group.
Most modern ransomware groups follow through on publication threats — stolen data appears on the group's leak site, is often mirrored to Telegram and dark web forums, and may be sold to third parties. Recovery becomes limited to whatever you can rebuild from backups.
Backups protect against file loss but not against data theft. Most modern ransomware groups exfiltrate sensitive data BEFORE encryption and threaten to publish it regardless of your recovery capability. This is why leak-site publication and negotiation still matter even for organisations with clean, offline backups — and why "we can just restore from backup" rarely tells the full story.
In most jurisdictions, yes — reporting is a standard part of a ransomware incident and, in some cases, legally required. In the US, that means the FBI (via IC3 or a local field office) and CISA. In the EU, national CERT and cybercrime units. Reporting does not obligate you to any specific recovery path but does open access to threat intelligence and, occasionally, decryption tools recovered by law enforcement.
Yes. We’ve handled 1,700+ incidents across ransomware, BEC and data-leak extortion. We identify the variant, decide decrypt vs. clean verified restore, and guide a controlled return to operations. When needed, we support negotiation & compliance—always legally and with a clear audit trail.
Yes. We produce insurer-ready incident reports with a defensible timeline, scope, likely entry path, exfiltration assessment, actions taken, and chain-of-custody. We can join the adjuster call, map our findings to your carrier’s forms, and provide GDPR/NIS2 notifications where required. Final acceptance always depends on the policy and carrier, but our packages are designed to speed up approvals and reduce back-and-forth.
MSPs keep IT running; they’re not built for evidence handling and incident triage. Insurer panels optimize claims, not necessarily speed & clarity for your business. We work alongside both: kick off in ≤2h, run forensic triage with chain-of-custody, coordinate safe containment, and deliver executive- and insurer-ready findings—without taking your environment hostage.
Because it turns chaos into fast, safe recovery. We cut downtime and limit damage while preserving evidence. Within ≤48h you get a forensic triage pack (timeline, likely entry path, scope, decrypt-vs-clean-restore decision, go-live criteria) so leadership can act with confidence. Result: controlled, verified restart—not guesswork.