CTIPilot

Rhysida

actor · actor:rhysida

Ransomware-as-a-service extortion operator active since at least May 2023 (British Library attack); per the CISA/FBI/Multi-State ISAC joint advisory (AA23-319A, originally November 2023, updated 2025-04-30), initial-access techniques include compromising internal VPN access points using valid credentials at organizations lacking MFA, and separately deploying Gootloader malware. Claimed a Landeshauptstadt Stuttgart municipal-data theft in May 2026 that the city disputed as a confirmed incident; named by Der Spiegel (via heise online, 2026-08-29) as the actor behind the August 2026 Berlin state-administration Landesnetz compromise and ransom demand, an attribution Berlin's Senate administration has not confirmed.

Coverage timeline
4
first 2026-05-20 → last 2026-08-30
Peak priority
high
3 high · 1 notable
Sources cited
17
14 hosts
Sections touched
1
active-threats
Co-occurring entities
7
see Co-occurring entities below
ATT&CK techniques
6
pinned v19.2 · see below
2026-05-204 appearances2026-08-30

ATT&CK techniques

6 techniques observed across 3 entries, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-05-23/rhysida-claims-stuttgart-municipal-data-theft-for-5-btc-city · ATT&CK page ↗

T1566Phishing×2

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-08-30/berlin-landesnetz-rhysida-extortion-phishing-vector · 2026-05-23/rhysida-claims-stuttgart-municipal-data-theft-for-5-btc-city · ATT&CK page ↗

Execution TA0002

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-06-25/mistic-backdoor-signed-defender-dll-sideloading-and-in-memor · ATT&CK page ↗

Persistence TA0003

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-05-23/rhysida-claims-stuttgart-municipal-data-theft-for-5-btc-city · ATT&CK page ↗

Stealth TA0005

T1036.005Masquerading: Match Legitimate Resource Name or Location×1

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.

Evidence: 2026-06-25/mistic-backdoor-signed-defender-dll-sideloading-and-in-memor · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-06-25/mistic-backdoor-signed-defender-dll-sideloading-and-in-memor · ATT&CK page ↗

Collection TA0009

T1074.001Data Staged: Local Data Staging×1

Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location.

Evidence: 2026-05-23/rhysida-claims-stuttgart-municipal-data-theft-for-5-btc-city · ATT&CK page ↗

Impact TA0040

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-08-30/berlin-landesnetz-rhysida-extortion-phishing-vector · ATT&CK page ↗

Story timeline

  1. 2026-08-30Berlin's state government confirms an extortion attempt after a phishing click opens the shared Landesnetz; media reporting names Rhysida
    active-threatsBerlin confirms extortion after a phishing click reaches the shared state network; media reports name Rhysida
  2. 2026-06-25"Mistic" backdoor: signed-Defender DLL sideloading and in-memory tradecraft by access broker Woodgnat/KongTuke
    active-threats
  3. 2026-05-23Rhysida claims Stuttgart municipal-data theft for 5 BTC; city denies a confirmed incident
    active-threats
  4. 2026-05-20Microsoft DCU disrupts Fox Tempest malware-signing-as-a-service feeding Rhysida, INC, Qilin and Akira ransomware operations
    active-threats

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

attributed activity

Where this entity is cited

  • active-threats4

Source distribution

  • heise.de4 (24%)
  • berliner-zeitung.de1 (6%)
  • blogs.microsoft.com1 (6%)
  • borncity.com1 (6%)
  • broadcom.com1 (6%)
  • cisa.gov1 (6%)
  • csoonline.com1 (6%)
  • dexpose.io1 (6%)
  • other6 (35%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (17)

Entries about Rhysida (4)

2026-08-30 · view entry permalink →

HIGHupdatedNATOB2

Berlin's state government confirms an extortion attempt after a phishing click opens the shared Landesnetz; media reporting names Rhysida

Germany's Berlin state administration is the target of a live extortion attempt following a compromise of its Landesnetz, the shared network serving every Senate department and state agency; the attack became public knowledge on 2026-08-14 (translated from German) (Berliner Zeitung, 2026-08-28), the same day the two affected departments were disconnected from the network as a containment measure (Der Tagesspiegel, 2026-08-28). Investigative reporting, not an official technical disclosure, is the first to name a mechanism: the attackers apparently gained access to the Landesnetz through an employee's click on a phishing email (translated from German) (Der Tagesspiegel, 2026-08-28). Forensic investigators found the actual data exfiltration ran between 2026-08-07 and 2026-08-12 (Security Affairs, 2026-08-29), several days before the two affected departments were disconnected.

Der Spiegel reported, citing security-industry sources, that the ransomware group Rhysida is behind the attack (heise online, 2026-08-29), an attribution Berlin's Senate administration has declined to confirm, citing investigative-tactical reasons (heise online, 2026-08-29). Rhysida's own dark-web leak site independently posted an entry titled "Berlin, Germany" on 2026-08-28 claiming 5.79 terabytes of data across roughly 1.44 million files, including personal data on 12,076 individuals, more than 5,000 personnel files, plaintext credentials for internal systems, disciplinary and court records, Bundesrat committee protocols, and vulnerability analyses concerning Berlin's water supply (Security Affairs, 2026-08-29). Rhysida demanded 30 Bitcoin, about EUR 2 million (translated from German) (heise online, 2026-08-29), with a one-week ultimatum running from 2026-08-28 (translated from German) (Der Tagesspiegel, 2026-08-28); Berlin's Governing Mayor Kai Wegner and Interior Senator Iris Spranger jointly confirmed the extortion attempt and publicly refused to pay, stating the state of Berlin will not submit to extortion (Security Affairs, 2026-08-29). Whether the affected systems were also encrypted, not only exfiltrated, is disputed: one outlet attributes to unnamed "experts" the claim that the Rhysida ransomware was the tool used to both encrypt the systems and steal the data (translated from German) (BornCity, 2026-08-29), while every other cited source describes only data theft and extortion without confirming encryption; this entry does not assert that encryption occurred.

CrowdStrike is conducting a forensic investigation across every Senate department and state agency network-wide, an effort Tagesspiegel's sources expect to take several more days (Der Tagesspiegel, 2026-08-28). The department networks disconnected on 2026-08-14 were reconnected on 2026-08-23, but staff report continuing operational degradation days later, with many now working over private internet connections because the corporate network remains impaired; the same reporting flags that workaround as a new, self-inflicted security exposure (Der Tagesspiegel, 2026-08-28). Rhysida has run this extortion pattern against public-sector targets before, including an earlier 2026 claim against the city of Stuttgart (translated from German) (heise online, 2026-08-29); per the joint CISA/FBI/Multi-State ISAC advisory on the group, current as of its 2025-04-30 update, its initial-access techniques include compromising internal VPN access points using valid credentials at organizations lacking multi-factor authentication, and separately deploying Gootloader malware (CISA, 2025-04-30).

Triage: the confirmed mechanism, a user-driven phishing-email click followed by multi-day bulk data exfiltration, surfaces at the point of delivery in mail-flow and attachment-sandboxing logs, and in network-egress and data-loss-prevention telemetry as a sustained high-volume outbound transfer from a single department's network segment; neither cited source states what executed after the click, so no process-level discriminator is offered here.

The attackers apparently gained access to the Landesnetz through an employee's click on a phishing email.

Der Tagesspiegel 2026-08-28

“The state of Berlin will not submit to extortion,” Berlin Mayor Kai Wegner and Berlin's interior senator, Iris Spranger, said in a joint statement on Friday, before the ransomware group claimed the attack on their Tor data leak site.

The ransomware group Rhysida claimed responsibility on its leak site August 28, posting an entry titled simply “Berlin, Germany” and claiming 5.79 terabytes of data across roughly 1.44 million files, with personal information on 12,076 individuals allegedly included.

Security Affairs 2026-08-29

Experts identified the ransomware Rhysida as the tool with which the systems were encrypted and the data stolen.

BornCity 2026-08-29

All files have been uploaded to the publicly accessible area, have fun browsing, data hunters!

Rhysida leak-site posting, via heise online

Based on what I can see here now, they have put the complete dataset online for everyone to view

Joachim Selzer, Chaos Computer Club spokesperson, via heise online (dpa)

Among the data that is viewable is, for example, the application for a new phone, including the signature of the administrative employee.

heise online (dpa)

the ministry points only to the existing constitutional framework.

heise online, citing the Federal Interior Ministry's (BMI) written reply

Until now, the BSI has only been constitutionally permitted to assist the states in defending against serious cyberattacks after an explicit request for administrative assistance. In addition, lengthy bilateral agreements had to be concluded, and these still do not exist with all 16 federal states today.

heise online 2026-08-29
Updaterun 2026-09-05T0409Z-intelupdated_atsourcesevidencebody

Rhysida's one-week ultimatum expired on 2026-09-04 at roughly 15:35 local time; the Berlin Senate had publicly committed not to pay, and about an hour after the deadline the group published the full stolen dataset on its darknet leak site, replacing the prior partial "auction" listing (heise online, 2026-09-04). Chaos Computer Club spokesperson Joachim Selzer confirmed the complete dataset (including personnel files and documents Selzer describes seeing directly, such as employment references) is now publicly accessible to anyone. Whether the dataset actually contains the drinking-water vulnerability analyses and administration credentials the group had earlier claimed remains unverified by any party this entry cites: Left-party parliamentary faction leader Tobias Schulze stated the Senate now has the opportunity to check whether the prior assumptions about the leaked data are accurate, and should notify affected individuals and organizations as quickly as possible once it does. No further technical root-cause detail beyond the phishing vector has been disclosed by the Senate.

Updaterun 2026-09-06T0409Z-intelupdated_atsourcesevidencebody

A structural consequence of this incident has now surfaced at the federal level. Asked in a Bundestag inquiry whether, given ongoing severe attacks on states and municipalities, the government would bring forward a constitutional amendment planned earlier by the previous coalition to make the BSI a true central authority for cyber incidents, the Federal Interior Ministry pointed only to the existing constitutional framework (heise online, 2026-09-03). Under that framework, the BSI may assist a state in defending against a serious cyberattack only after that state explicitly requests administrative assistance, and durable bilateral cooperation agreements (a precondition the ministry itself confirms do not yet exist with all 16 federal states) still gate faster support; in practice the BSI has repeatedly had to help first and formalise the legal basis afterward (heise online, 2026-09-03). The ministry points instead to its 14 existing cooperation agreements, its NIS2-transposition-driven expansion of BSI's powers, and increased staffing and budget as sufficient. Green-faction deputy chair Konstantin von Notz, who filed the inquiry, called the reversal "devastating for Germany's IT security" (translated from German) given the still-unfolding fallout from this exact incident. The tension is directly transferable to any federated cyber-incident-response model, including Switzerland's own federal/cantonal/communal cooperation structure with BACS: a central technical authority's ability to help is gated by a request-and-agreement process rather than by its own capacity to act.

Separately, on the incident itself, the Chaos Computer Club's Joachim Selzer identified specific record types now visible in the fully-published leak beyond the personnel-and-employment-reference material already recorded here: an internal request form for a new mobile phone bearing the requesting employee's handwritten signature, which Selzer noted gives a criminal a usable signature sample (heise online, 2026-09-04).

incident30 Aug 04:35Zmulti-sourceOpen finding ↗

2026-06-25 · view entry permalink →

HIGH

"Mistic" backdoor: signed-Defender DLL sideloading and in-memory tradecraft by access broker Woodgnat/KongTuke

Symantec disclosed Backdoor.Mistic (also tracked as MLTBackdoor), deployed since April 2026 by initial-access broker Woodgnat (a.k.a. KongTuke) that sells footholds to ransomware affiliates including Qilin, Interlock, Rhysida, Akira, 8Base and Black Basta (Symantec, 2026-06-24 · SecurityWeek, 2026-06-24). Mistic achieves DLL sideloading via a digitally-signed Microsoft Defender executable (MpExtMs.exe) loading a malicious EndpointDlp.dll (T1574.002, T1036.005), so its activity reads as legitimate Defender behaviour to EDR. Per Symantec it also supports in-memory tradecraft and file manipulation/arbitrary code execution with a kill switch for stealth. Delivery uses ClickFix / FileFix / CrashFix lures (fake CAPTCHAs, browser-crash pages, Teams IT-helpdesk impersonation directing victims to run PowerShell). Why it matters to us: The downstream affiliates are all active public-sector ransomware actors. Detection is precise: legitimate Defender DLPs load from %ProgramFiles%\Windows Defender\ under a Microsoft certificate, any EndpointDlp.dll loaded from a user-writable path or with a non-Microsoft signature is high-confidence (Sysmon EID 7). Pair with EID 1 parent-chains for PowerShell spawned by Teams/Office clients.

Mistic achieves DLL sideloading via a digitally-signed Microsoft Defender executable (MpExtMs.exe) loading a malicious DLL named EndpointDlp.dll

CSO Online citing Symantec

Woodgnat maintains relationships with six ransomware families including Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta

SecurityWeek
threat25 Jun 04:59Zmulti-sourceOpen finding ↗

2026-05-23 · view entry permalink →

NOTABLE

Rhysida claims Stuttgart municipal-data theft for 5 BTC; city denies a confirmed incident

The Rhysida ransomware-as-a-service group listed Landeshauptstadt Stuttgart; the Baden-Württemberg state capital (~600,000 residents), on its dark-web leak site in mid-May 2026 (DeXpose dates the listing to 2026-05-19; Heise (2026-05-21) covers the leak-site listing and Stuttgart's response without anchoring the original posting date), demanding 5 Bitcoin (~€333,000) for exclusive access to allegedly stolen documents and publishing heavily downscaled previews of scanned invoices and faxes attributed to Stuttgart's administrative systems (Heise Online (EN), 2026-05-21 · DeXpose, 2026-05-20). The city's response is measured: published material is "currently being examined together with the responsible authorities" and Stuttgart has "no indications of a cyber incident at this time", with further comment declined while investigation continues. No vulnerability or initial access vector has been disclosed; the claim appears to be data-exfiltration-only with city portals and operational systems unaffected, consistent with Rhysida's pattern since the British Library (2023) and the German charity Welthungerhilfe (2025).

Defender vantage with the city's denial in mind: confidence in the claim is MEDIUM; the only corroboration is press coverage of the leak-site listing itself. Hunt rather than respond: Rhysida tends to gain initial access through phishing (T1566) or external VPN exploitation (T1133), executes living-off-the-land via cmd.exe / PowerShell with scheduled-task persistence, and stages data in unusual directories before exfiltration (T1074.001). DACH municipal SOCs should treat the listing as a forcing function to re-check VPN patch levels, password-spray detection on the on-prem identity edge, and any unexplained outbound bursts from file servers and DFS shares since 2026-05-10. South Korean researchers' 2024 free Rhysida decryptor exploited an encryption flaw that the group has since reworked; no current decryptor is publicly known for 2026 variants if encryption does follow.

Why it matters to us: German municipal targeting bleeds into Swiss DACH context (shared partner networks, fediplomatic exchanges); the Stuttgart pattern (data theft only, leak-site posting, city denies) is increasingly common and the right response is hunt-without-confirming, not wait-for-a-victim-statement.

incident23 May 05:00Zmulti-sourceOpen finding ↗

Earlier coverage (1)