We conducted a research study on the activity of the group responsible for spreading the Rhysida. Most of the information was sourced from open sources and cybersecurity research. We collected indicators observed in the group’s attacks and analyzed discovered malware samples and tools used in their operations. It is not an in-depth analysis of Rhysida tactics and tools but a collection of indicators to help identify similar activity, focusing on recent operations.
Rhysida is a hacker group that emerged in 2023 and gained notoriety after an attack on the Chilean Army, followed by the publication of stolen data. The group operates under a "Ransomware as a Service" (RaaS) model, where ransom payments are distributed among members and affiliates. Their goal is financial gain, and they actively target organizations in sectors such as education, healthcare, manufacturing, IT, and government structures.
The group is likely based in a CIS country, as they avoid attacks on companies within these regions. Rhysida operates with no motivation or connection to government structures, as evidenced by its purely financial orientation.
Likely CIS (Commonwealth of Independent States)
Financial gain
2023
Places a ransom note image in the directory C:\Users\Public\bg.jpg and executes a command to change the desktop wallpaper, setting this image as the background.
cmd.exe /c reg add "HKCU\Control Panel\Desktop" /v Wallpaper /t REG_SZ /d "C:\Users\Public\bg.jpg" /f
With the following TI lookup query, we can search through public tasks and identify this malicious activity.
TI lookup:
commandLine:"cmd.exe /c reg add*Wallpaper*C:\\Users\\Public\\bg.jpg*" AND commandLine:"?HKCU\\Control Panel\\Desktop?" AND threatName:"rhysida"
This PowerShell command runs with a hidden window, waits for 500 milliseconds, and then forcibly deletes the specified file (rhysida.exe) at the given path. It suppresses any error messages during execution to avoid detection or interruptions.
powershell.exe -WindowStyle Hidden -Command Sleep -Milliseconds 500; Remove-Item -Force -Path "C:\Users\admin\AppData\Local\Temp\C:\Users\admin\AppData\Local\Temp\d5c2f87033a5baeeb1b5b681f2c4a156ff1c05ccd1bfdaf6eae019fc4d5320ee.exe" -ErrorAction SilentlyContinue
With the following TI lookup query, we can search through public tasks and identify this malicious activity.
TI lookup:
commandLine:"*-WindowStyle Hidden -Command Sleep -Milliseconds *; Remove-Item -Force -Path* -ErrorAction SilentlyContinue;"
SHA-256: d5c2f87033a5baeeb1b5b681f2c4a156ff1c05ccd1bfdaf6eae019fc4d5320ee
Sample: ANY.RUN
SHA-256: 250e81eeb4df4649ccb13e271ae3f80d44995b2f8ffca7a2c5e1c738546c2ab1
Sample: ANY.RUN
SHA-256: a864282fea5a536510ae86c77ce46f7827687783628e4f2ceb5bf2c41b8cd3c6
Sample: ANY.RUN
SHA-256: b55ecbddcbed916481ad537807cd3e33cb71814be6ce8e03eb63b629ccb8c692
Sample: ANY.RUN
SHA-256: 35242021013c58d185decee8288f897349b02ee4596c3bb2e686de5799b4dfc8
SHA-256: 10e175e5a28939fc31648772b53181b8ef59fdd051174e8da8a8a832420747de
Sample: ANY.RUN
This PowerShell command retrieves information about the computer system using the WMI class win32_computersystem and extracts the value of the domain property. It outputs only the domain name associated with the current system, excluding any other details.
powershell.exe -command "get-wmiobject win32_computersystem | select-object -expandproperty domain"
With the following TI lookup query, we can search through public tasks and identify this malicious activity.
TI lookup:
commandLine:"powershell.exe -command ?get-wmiobject * | select-object *"
69b3d913a3967153d1e91ba1a31ebed839b297ed338d4f4ec714359d589918cee1adad12ef231907b07f6a5f61834a57304ad4d885bd37d8e1badba8a864282fea5a536510ae86c77ce46f7827687783628e4f2ceb5bf2c41b8cd3c67abc07e7f56fc27130f84d1c7935a0961bd58cb92543857b275ea5c6d332ab279498a5b772bd2bd4eda3a5b8ec86dd5741786ed791d43698bb92a26239649fa040a3c6894758016a65afec7b6acd40174947cf015875b169b6509a279941e854b022dd8ec27a865b3ab1f0bd2ea1e8f7298b5ef9348c5ac96dc78c00a622c3df5e038b8ed41b2de68e6c350df96143540d36edf1b9d9d25d91778855cafa8a6a1034cdc499b4c551e43bc259d10928d75293214de52c40ca449c7285660541c84ac5d6fe78a6bffe14ee9ad241517ef72a4c6561fb848f6d659e764rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad[.]onion1A9C27E5BE8C58DA1C02FC4245A07831D5D431CD1A91CD35D2DD0AD62DA71CD0BB0E1FCFF8CCF54C6F9ECFD4BBB6757F6A25CB0E7A173D12CF0F402A3AE706FF6F74E05E24DD2E4E60E5FB50F73FC720EE826A43F2F0056E5B88724FA06FBAB6903B00A15EFF9B494947896F222BD5B093A63AA1F340815823645FD57BD61DE3BC0340007F3A9831CB35766F2EB42DE81D13AEB99B3A8C07DEE0BB8B000CB962A3942D213548573AF8CB07C13547C0D52D1C3D72365276D6623B3951BD6D1B26633fa85bb234a75927b23417313e51a4c155e12f71da3959e168851a600b010078163d5c16f64caa5a14784323fd51451b8c831c73396b967b4e35e6879937b1c4978cd5d750a2985da9b58db137fc74d28422f1e087fd77642faa7efe7b5974e34b9442f825a16d7f6557193426ae7a18899ed46d3b896f6e435736727618397766464d0f2f91b82b557ac656ab82e15cae7896b1d8c98632ca53c15cf06c4918784e25bd24192ce4e999538be96898558660659e3c624a5f27857784cd7e15.39.222[.]675.255.99[.]5951.77.102[.]106108.62.118[.]136108.62.141[.]161146.70.104[.]249156.96.62[.]58157.154.194[.]6b25b87cfcedc69e27570afa1f4b1ca85aab07fd416c5d0228f1fe32886e0a9a648f559e00c472d9ffe3965ab92c6d298f8fb3a3f0d6d203cd2069bfca4bf3a57edfae1a69522f87b12c6dac3225d930e4848832e3c551ee1e7d31736bf4525ef201d8e77ccc2575d910d47042a986480b1da28cf0033e7ee726ad9d45ccf4daaa48ac157609888471bf8578fb8b2aef6b0068f7e0742fccf2e0e288b0b2cfdfbde73b73eeb156f877de61f4a6975d06759292ed69f31aaf06c9811f3311e03e7951b1b5fd5cb13cde159cebc7c60465587e2061363d1d8847ab78b6c4fba7501fdadb6e15c52c41a31e3c22659dd490d5b616e017d1b1aa6070008ce09ed27ead689cb1dbd2e4c06cd15e51a6871c406c595790ddcdcd7dc8d0401c7183720e554f523914cdbaed8b17527170502199c185bd69a41c81102c50dbb0e5e5a78dd3a816fe5d545a80e4639b34b90d92d1039eb71ef59e6e81b3c0e043a45b751c8329bcbadc7f81539a4969ca13f0be5b8eb7652b912324a1926fc9bfb6ec005abe922312978a53c92a49fefd2c9f9cc098767b36f0e4d2e829d24725df65bc214243dc8b991f5f8b3c0f233ca2110a1e03a1d716c3f51e88faf1d59b8242d3297ba47558c99e18c2c6449be804b5e765c48d3a70ceaa04c1e0fae67ff1d7178d5ef168f83b55d2cbd2426afc5e6fa8161270fa6a2a312831332dc472c95dfa42d3247f03dcd7b9335344ebba76a0b92370f32f1cb0e480c734da52db2bd8df60ed05f5d462767b3986583188000143f0eb24f7d89605523a28950e72e6b9039a5e55b4caf47a248a10abd009617684e969dbe5c448d087ee8178262aaab68636dcdb9bd39b6014434190a9949dedf633726fdb470e95cc47cdaa47c1964b969f8d950068f46a04e77ad6637c680cccf5d703a1828fbd6bdca513268af4f2170f6ed5d50cf9d07db73eaa92c5405f6b1bf670028c602c605dfa7d4fcb80ef0801d1f718d219930e57794bdadf9dda61406294b0759038cef282f7544b44b92285355b4a82313074999bd8fa1332b1ed00034e63bd2a0d0367e2622f35d75cf1404226738489c2a67852d51dbf96574f33e44e509bc265b950d495da79bb45740013fd3ad690c73cf0ad26c6716d4e9d1581b47c22fb7518b1d3bf9cfb8f9e91234bf8fbb7db583e1aacbf36c5f740d012c8321f221066cc68107031bd8b6bc1ee95a922e178075fb771066db4ab1bd70c7016f794709d514ab1c7f11500f016cda9ca77dfe03ce15004157727bb43ba66f00ceb215362c9b3d199f000edaa8d612813b6c07d17d25670163e0f66453b42d2f157bf2e42007806ebc6bb9d114acc8e43d1ddbd5c129055528a93f1e3fab0ecdf73a8a7ba9713dc4c3e216d7e5db448f559e00c472d9ffe3965ab92c6d298f8fb3a3f0d6d203cd2069bfca4bf3a57edfae1a69522f87b12c6dac3225d930e4848832e3c551ee1e7d31736bf4525ef 078163d5c16f64caa5a14784323fd51451b8c831c73396b967b4e35e6879937b 201d8e77ccc2575d910d47042a986480b1da28cf0033e7ee726ad9d45ccf4daa a48ac157609888471bf8578fb8b2aef6b0068f7e0742fccf2e0e288b0b2cfdfb de73b73eeb156f877de61f4a6975d06759292ed69f31aaf06c9811f3311e03e7 951b1b5fd5cb13cde159cebc7c60465587e2061363d1d8847ab78b6c4fba7501 fdadb6e15c52c41a31e3c22659dd490d5b616e017d1b1aa6070008ce09ed27ea d689cb1dbd2e4c06cd15e51a6871c406c595790ddcdcd7dc8d0401c7183720e 554f523914cdbaed8b17527170502199c185bd69a41c81102c50dbb0e5e5a78d d3a816fe5d545a80e4639b34b90d92d1039eb71ef59e6e81b3c0e043a45b751c 8329bcbadc7f81539a4969ca13f0be5b8eb7652b912324a1926fc9bfb6ec005a be922312978a53c92a49fefd2c9f9cc098767b36f0e4d2e829d24725df65bc21 4243dc8b991f5f8b3c0f233ca2110a1e03a1d716c3f51e88faf1d59b8242d329 7ba47558c99e18c2c6449be804b5e765c48d3a70ceaa04c1e0fae67ff1d7178d 5ef168f83b55d2cbd2426afc5e6fa8161270fa6a2a312831332dc472c95dfa42 d3247f03dcd7b9335344ebba76a0b92370f32f1cb0e480c734da52db2bd8df60 ed05f5d462767b3986583188000143f0eb24f7d89605523a28950e72e6b9039a 5e55b4caf47a248a10abd009617684e969dbe5c448d087ee8178262aaab68636 dcdb9bd39b6014434190a9949dedf633726fdb470e95cc47cdaa47c1964b969f 8d950068f46a04e77ad6637c680cccf5d703a1828fbd6bdca513268af4f2170f 6ed5d50cf9d07db73eaa92c5405f6b1bf670028c602c605dfa7d4fcb80ef0801 d1f718d219930e57794bdadf9dda61406294b0759038cef282f7544b44b92285 355b4a82313074999bd8fa1332b1ed00034e63bd2a0d0367e2622f35d75cf140 4226738489c2a67852d51dbf96574f33e44e509bc265b950d495da79bb457400 13fd3ad690c73cf0ad26c6716d4e9d1581b47c22fb7518b1d3bf9cfb8f9e9123 4bf8fbb7db583e1aacbf36c5f740d012c8321f221066cc68107031bd8b6bc1ee 95a922e178075fb771066db4ab1bd70c7016f794709d514ab1c7f11500f016cd a9ca77dfe03ce15004157727bb43ba66f00ceb215362c9b3d199f000edaa8d61 2813b6c07d17d25670163e0f66453b42d2f157bf2e42007806ebc6bb9d114acc 8e43d1ddbd5c129055528a93f1e3fab0ecdf73a8a7ba9713dc4c3e216d7e5db4domain: codeforprofessionalusers[.]com
SHA-256: 0a7fd836d36ed8e8e9aa7bc41fdc9242333e8469059dec8886b7d935f3651679
ip: 173.46.80[.]206
SHA-256: b55ecbddcbed916481ad537807cd3e33cb71814be6ce8e03eb63b629ccb8c692
CVE-2020-1472rule rw_rhysida {
meta:
author = "Alex Delamotte"
description = "Rhysida ransomware detection."
sample = "69b3d913a3967153d1e91ba1a31ebed839b297ed"
reference = "https://s1.ai/rhys"
strings:
$typo1 = { 63 6D 64 2E 65 78 65 20 2F 63 20 72 65 67 20 64 65 6C 65 74 65 20 22 48 4B 43 55 5C 43 6F 6E 74 74 6F 6C 20 50 61 6E 65 6C 5C 44 65 73 6B 74 6F 70 22 }
$cmd1 = { 63 6D 64 2E 65 78 65 20 2F 63 20 72 65 67 20 61 64 64 20 22 48 4B 43 55 5C 53 6F 66 74 77 61 72 65 5C 4D 69 63 72 6F 73 6F 66 74 5C 57 69 6E 64 6F 77 73 5C 43 75 72 72 65 6E 74 56 65 72 73 69 6F 6E 5C 50 6F 6C 69 63 69 65 73 5C 41 63 74 69 76 65 44 65 73 6B 74 6F 70 }
$cmd2 = { 63 6D 64 2E 65 78 65 20 2F 63 20 72 65 67 20 61 64 64 20 22 48 4B 4C 4D 5C 53 6F 66 74 77 61 72 65 5C 4D 69 63 72 6F 73 6F 66 74 5C 57 69 6E 64 6F 77 73 5C 43 75 72 72 65 6E 74 56 65 72 73 69 6F 6E 5C 50 6F 6C 69 63 69 65 73 5C 53 79 73 74 65 6D 22 20 2F 76 20 57 61 6C 6C 70 61 70 65 72 20 2F 74 20 52 45 47 5F 53 5A 20 2F 64 20 22 43 3A 5C 55 73 65 72 73 5C 50 75 62 6C 69 63 5C 62 67 2E 6A 70 67 22 20 2F 66 }
$byte1 = { 48 8D 05 72 AA 05 00 48 8B 00 8B 95 }
$byte2 = { 48 8D 15 89 CF 03 00 48 89 C1 E8 F9 1C 03 00 44 }
condition:
2 of them
}
rule RhysidaRansomware {
meta:
description = "rule to detect Rhysida Ransomware"
author = "ShadowStackRe.com"
date = "2023-12-12"
Rule_Version = "v1"
malware_type = "ransomware"
malware_family = "Rhysida"
License = "MIT License, https://opensource.org/license/mit/"
strings:
$strShadowCopy = " vssadmin.exe Delete Shadows"
$strRhsyida01 = "Rhysida-0.1"
$strRhysida = "rhysida"
$strRegKey1 = "cmd.exe /c reg delete \"HKCU\\Contol Panel\\Desktop"
$strRegKey2 = "Policies\\ActiveDesktop\" /v NoChangingWallPaper"
$strRunDll32 = "rundll32.exe user32.dll,UpdatePerUserSystemParameters"
$strPDF = "CriticalBreachDetected.pdf"
condition:
all of them
}
rule INDICATOR_KB_ID_Ransomware_Rhysida {
meta:
author = "ditekShen"
description = "Detects files referencing identities associated with Rhysida ransomware"
strings:
$s1 = "SethZemlak@onionmail.org" ascii wide nocase
$s2 = "JacquieKunze@onionmail.org" ascii wide nocase
condition:
any of them
}
SigmaHQ Potentially Suspicious Desktop Background Change Via Registry
title: Potentially Suspicious Desktop Background Change Via Registry
id: 85b88e05-dadc-430b-8a9e-53ff1cd30aae
related:
- id: 8cbc9475-8d05-4e27-9c32-df960716c701
type: similar
status: test
description: |
Detects registry value settings that would replace the user's desktop background.
This is a common technique used by malware to change the desktop background to a ransom note or other image.
references:
- https://www.attackiq.com/2023/09/20/emulating-rhysida/
- https://research.checkpoint.com/2023/the-rhysida-ransomware-activity-analysis-and-ties-to-vice-society/
- https://www.trendmicro.com/en_us/research/23/h/an-overview-of-the-new-rhysida-ransomware.html
- https://www.virustotal.com/gui/file/a864282fea5a536510ae86c77ce46f7827687783628e4f2ceb5bf2c41b8cd3c6/behavior
- https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.WindowsDesktop::Wallpaper
- https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.ControlPanelDisplay::CPL_Personalization_NoDesktopBackgroundUI
author: Nasreddine Bencherchali (Nextron Systems), Stephen Lincoln @slincoln-aiq (AttackIQ)
date: 2023-12-21
tags:
- attack.defense-evasion
- attack.impact
- attack.t1112
- attack.t1491.001
logsource:
product: windows
category: registry_set
detection:
selection_keys:
TargetObject|contains:
- 'Control Panel\Desktop'
- 'CurrentVersion\Policies\ActiveDesktop'
- 'CurrentVersion\Policies\System'
selection_values_1:
TargetObject|endswith: 'NoChangingWallpaper'
Details: 'DWORD (0x00000001)' # Prevent changing desktop background
selection_values_2:
TargetObject|endswith: '\Wallpaper'
selection_values_3:
TargetObject|endswith: '\WallpaperStyle'
Details: '2' # Stretch
filter_main_svchost:
# Note: Excluding GPO changes
Image|endswith: '\svchost.exe'
condition: selection_keys and 1 of selection_values_* and not 1 of filter_main_*
falsepositives:
- Administrative scripts that change the desktop background to a company logo or other image.
level: medium