Rhysida Attacks

Overview

We conducted a research study on the activity of the group responsible for spreading the Rhysida. Most of the information was sourced from open sources and cybersecurity research. We collected indicators observed in the group’s attacks and analyzed discovered malware samples and tools used in their operations. It is not an in-depth analysis of Rhysida tactics and tools but a collection of indicators to help identify similar activity, focusing on recent operations.

About Rhysida

Rhysida is a hacker group that emerged in 2023 and gained notoriety after an attack on the Chilean Army, followed by the publication of stolen data. The group operates under a "Ransomware as a Service" (RaaS) model, where ransom payments are distributed among members and affiliates. Their goal is financial gain, and they actively target organizations in sectors such as education, healthcare, manufacturing, IT, and government structures.

The group is likely based in a CIS country, as they avoid attacks on companies within these regions. Rhysida operates with no motivation or connection to government structures, as evidenced by its purely financial orientation.

Origin Country

Likely CIS (Commonwealth of Independent States)

Motivation

Financial gain

First Seen

2023

Information on Targeted Companies

  • Over 100 companies
  • Model: RaaS (Ransomware as a Service)

Industries Attacked

  • Education
  • Healthcare
  • Military
  • Entertainment
  • Energy

COBALTSTRIKE

  • Trend Micro - Overview of Rhysida Ransomware

AnyDesk

  • CISA Cybersecurity Advisory

SECRETSDUMP

  • CISA Cybersecurity Advisory

RHYSIDA

  • SentinelOne - Rhysida Ransomware Overview
  • Cronup - Rhysida Attack
  • ShadowStack - Rhysida Analysis

Places a ransom note image in the directory C:\Users\Public\bg.jpg and executes a command to change the desktop wallpaper, setting this image as the background.

cmd.exe /c reg add "HKCU\Control Panel\Desktop" /v Wallpaper /t REG_SZ /d "C:\Users\Public\bg.jpg" /f

With the following TI lookup query, we can search through public tasks and identify this malicious activity.

TI lookup: commandLine:"cmd.exe /c reg add*Wallpaper*C:\\Users\\Public\\bg.jpg*" AND commandLine:"?HKCU\\Control Panel\\Desktop?" AND threatName:"rhysida"

This PowerShell command runs with a hidden window, waits for 500 milliseconds, and then forcibly deletes the specified file (rhysida.exe) at the given path. It suppresses any error messages during execution to avoid detection or interruptions.

powershell.exe -WindowStyle Hidden -Command Sleep -Milliseconds 500; Remove-Item -Force -Path "C:\Users\admin\AppData\Local\Temp\C:\Users\admin\AppData\Local\Temp\d5c2f87033a5baeeb1b5b681f2c4a156ff1c05ccd1bfdaf6eae019fc4d5320ee.exe" -ErrorAction SilentlyContinue

With the following TI lookup query, we can search through public tasks and identify this malicious activity.

TI lookup: commandLine:"*-WindowStyle Hidden -Command Sleep -Milliseconds *; Remove-Item -Force -Path* -ErrorAction SilentlyContinue;"

  • SHA-256: d5c2f87033a5baeeb1b5b681f2c4a156ff1c05ccd1bfdaf6eae019fc4d5320ee

  • Sample: ANY.RUN

  • SHA-256: 250e81eeb4df4649ccb13e271ae3f80d44995b2f8ffca7a2c5e1c738546c2ab1

  • Sample: ANY.RUN

  • SHA-256: a864282fea5a536510ae86c77ce46f7827687783628e4f2ceb5bf2c41b8cd3c6

  • Sample: ANY.RUN

  • SHA-256: b55ecbddcbed916481ad537807cd3e33cb71814be6ce8e03eb63b629ccb8c692

  • Sample: ANY.RUN

SILENTKILL

  • Trend Micro - Overview of Rhysida Ransomware

  • Trend Micro - Ransomware Spotlight on Rhysida

  • SHA-256: 35242021013c58d185decee8288f897349b02ee4596c3bb2e686de5799b4dfc8

PORTSTARTER

  • Uncovering Rhysida Logpoint Report

  • SHA-256: 10e175e5a28939fc31648772b53181b8ef59fdd051174e8da8a8a832420747de

  • Sample: ANY.RUN

This PowerShell command retrieves information about the computer system using the WMI class win32_computersystem and extracts the value of the domain property. It outputs only the domain name associated with the current system, excluding any other details.

powershell.exe -command "get-wmiobject win32_computersystem | select-object -expandproperty domain"

With the following TI lookup query, we can search through public tasks and identify this malicious activity.

TI lookup: commandLine:"powershell.exe -command ?get-wmiobject * | select-object *"

IOC Summary

  • SentinelOne - Attack on Chilean Army
  • Cronup - Attack on Chilean Army
IOCs (Click to expand)
  • SHA-1: 69b3d913a3967153d1e91ba1a31ebed839b297ed
  • SHA-1: 338d4f4ec714359d589918cee1adad12ef231907
  • SHA-1: b07f6a5f61834a57304ad4d885bd37d8e1badba8
  • SHA-256: a864282fea5a536510ae86c77ce46f7827687783628e4f2ceb5bf2c41b8cd3c6

  • Trend Micro - Overview of Rhysida Ransomware
  • Trend Micro - Ransomware Spotlight on Rhysida
IOCs (Click to expand)
  • SHA-1: 7abc07e7f56fc27130f84d1c7935a0961bd58cb9
  • SHA-1: 2543857b275ea5c6d332ab279498a5b772bd2bd4
  • SHA-1: eda3a5b8ec86dd5741786ed791d43698bb92a262
  • SHA-1: 39649fa040a3c6894758016a65afec7b6acd4017
  • SHA-1: 4947cf015875b169b6509a279941e854b022dd8e
  • SHA-1: c27a865b3ab1f0bd2ea1e8f7298b5ef9348c5ac
  • SHA-1: 96dc78c00a622c3df5e038b8ed41b2de68e6c350
  • SHA-1: df96143540d36edf1b9d9d25d91778855cafa8a6
  • SHA-1: a1034cdc499b4c551e43bc259d10928d75293214
  • SHA-1: de52c40ca449c7285660541c84ac5d6fe78a6bff
  • SHA-1: e14ee9ad241517ef72a4c6561fb848f6d659e764
  • domain: rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad[.]onion

  • Talos Intelligence - Rhysida Ransomware
IOCs (Click to expand)
  • SHA-256: 1A9C27E5BE8C58DA1C02FC4245A07831D5D431CD1A91CD35D2DD0AD62DA71CD
  • SHA-256: 0BB0E1FCFF8CCF54C6F9ECFD4BBB6757F6A25CB0E7A173D12CF0F402A3AE706F
  • SHA-256: F6F74E05E24DD2E4E60E5FB50F73FC720EE826A43F2F0056E5B88724FA06FBAB
  • SHA-256: 6903B00A15EFF9B494947896F222BD5B093A63AA1F340815823645FD57BD61DE
  • SHA-256: 3BC0340007F3A9831CB35766F2EB42DE81D13AEB99B3A8C07DEE0BB8B000CB96
  • SHA-256: 2A3942D213548573AF8CB07C13547C0D52D1C3D72365276D6623B3951BD6D1B2

  • CISA Cybersecurity Advisory
IOCs (Click to expand)
  • SHA-256: 6633fa85bb234a75927b23417313e51a4c155e12f71da3959e168851a600b010
  • SHA-256: 078163d5c16f64caa5a14784323fd51451b8c831c73396b967b4e35e6879937b
  • SHA-256: 1c4978cd5d750a2985da9b58db137fc74d28422f1e087fd77642faa7efe7b597
  • SHA-256: 4e34b9442f825a16d7f6557193426ae7a18899ed46d3b896f6e4357367276183
  • SHA-256: 97766464d0f2f91b82b557ac656ab82e15cae7896b1d8c98632ca53c15cf06c4
  • SHA-256: 918784e25bd24192ce4e999538be96898558660659e3c624a5f27857784cd7e1
  • ip: 5.39.222[.]67
  • ip: 5.255.99[.]59
  • ip: 51.77.102[.]106
  • ip: 108.62.118[.]136
  • ip: 108.62.141[.]161
  • ip: 146.70.104[.]249
  • ip: 156.96.62[.]58
  • ip: 157.154.194[.]6

  • Detect.FYI - Rhysida Ransomware Detection Opportunities
IOCs (Click to expand)
  • SHA-256: b25b87cfcedc69e27570afa1f4b1ca85aab07fd416c5d0228f1fe32886e0a9a6
  • SHA-256: 48f559e00c472d9ffe3965ab92c6d298f8fb3a3f0d6d203cd2069bfca4bf3a57
  • SHA-256: edfae1a69522f87b12c6dac3225d930e4848832e3c551ee1e7d31736bf4525ef
  • SHA-256: 201d8e77ccc2575d910d47042a986480b1da28cf0033e7ee726ad9d45ccf4daa
  • SHA-256: a48ac157609888471bf8578fb8b2aef6b0068f7e0742fccf2e0e288b0b2cfdfb
  • SHA-256: de73b73eeb156f877de61f4a6975d06759292ed69f31aaf06c9811f3311e03e7
  • SHA-256: 951b1b5fd5cb13cde159cebc7c60465587e2061363d1d8847ab78b6c4fba7501
  • SHA-256: fdadb6e15c52c41a31e3c22659dd490d5b616e017d1b1aa6070008ce09ed27ea
  • SHA-256: d689cb1dbd2e4c06cd15e51a6871c406c595790ddcdcd7dc8d0401c7183720e
  • SHA-256: 554f523914cdbaed8b17527170502199c185bd69a41c81102c50dbb0e5e5a78d
  • SHA-256: d3a816fe5d545a80e4639b34b90d92d1039eb71ef59e6e81b3c0e043a45b751c
  • SHA-256: 8329bcbadc7f81539a4969ca13f0be5b8eb7652b912324a1926fc9bfb6ec005a
  • SHA-256: be922312978a53c92a49fefd2c9f9cc098767b36f0e4d2e829d24725df65bc21
  • SHA-256: 4243dc8b991f5f8b3c0f233ca2110a1e03a1d716c3f51e88faf1d59b8242d329
  • SHA-256: 7ba47558c99e18c2c6449be804b5e765c48d3a70ceaa04c1e0fae67ff1d7178d
  • SHA-256: 5ef168f83b55d2cbd2426afc5e6fa8161270fa6a2a312831332dc472c95dfa42
  • SHA-256: d3247f03dcd7b9335344ebba76a0b92370f32f1cb0e480c734da52db2bd8df60
  • SHA-256: ed05f5d462767b3986583188000143f0eb24f7d89605523a28950e72e6b9039a
  • SHA-256: 5e55b4caf47a248a10abd009617684e969dbe5c448d087ee8178262aaab68636
  • SHA-256: dcdb9bd39b6014434190a9949dedf633726fdb470e95cc47cdaa47c1964b969f
  • SHA-256: 8d950068f46a04e77ad6637c680cccf5d703a1828fbd6bdca513268af4f2170f
  • SHA-256: 6ed5d50cf9d07db73eaa92c5405f6b1bf670028c602c605dfa7d4fcb80ef0801
  • SHA-256: d1f718d219930e57794bdadf9dda61406294b0759038cef282f7544b44b92285
  • SHA-256: 355b4a82313074999bd8fa1332b1ed00034e63bd2a0d0367e2622f35d75cf140
  • SHA-256: 4226738489c2a67852d51dbf96574f33e44e509bc265b950d495da79bb457400
  • SHA-256: 13fd3ad690c73cf0ad26c6716d4e9d1581b47c22fb7518b1d3bf9cfb8f9e9123
  • SHA-256: 4bf8fbb7db583e1aacbf36c5f740d012c8321f221066cc68107031bd8b6bc1ee
  • SHA-256: 95a922e178075fb771066db4ab1bd70c7016f794709d514ab1c7f11500f016cd
  • SHA-256: a9ca77dfe03ce15004157727bb43ba66f00ceb215362c9b3d199f000edaa8d61
  • SHA-256: 2813b6c07d17d25670163e0f66453b42d2f157bf2e42007806ebc6bb9d114acc
  • SHA-256: 8e43d1ddbd5c129055528a93f1e3fab0ecdf73a8a7ba9713dc4c3e216d7e5db4

  • Orange Cyberdefense Report
IOCs (Click to expand)
  • SHA-256: 48f559e00c472d9ffe3965ab92c6d298f8fb3a3f0d6d203cd2069bfca4bf3a57
  • SHA-256: edfae1a69522f87b12c6dac3225d930e4848832e3c551ee1e7d31736bf4525ef
  • SHA-256: 078163d5c16f64caa5a14784323fd51451b8c831c73396b967b4e35e6879937b
  • SHA-256: 201d8e77ccc2575d910d47042a986480b1da28cf0033e7ee726ad9d45ccf4daa
  • SHA-256: a48ac157609888471bf8578fb8b2aef6b0068f7e0742fccf2e0e288b0b2cfdfb
  • SHA-256: de73b73eeb156f877de61f4a6975d06759292ed69f31aaf06c9811f3311e03e7
  • SHA-256: 951b1b5fd5cb13cde159cebc7c60465587e2061363d1d8847ab78b6c4fba7501
  • SHA-256: fdadb6e15c52c41a31e3c22659dd490d5b616e017d1b1aa6070008ce09ed27ea
  • SHA-256: d689cb1dbd2e4c06cd15e51a6871c406c595790ddcdcd7dc8d0401c7183720e
  • SHA-256: 554f523914cdbaed8b17527170502199c185bd69a41c81102c50dbb0e5e5a78d
  • SHA-256: d3a816fe5d545a80e4639b34b90d92d1039eb71ef59e6e81b3c0e043a45b751c
  • SHA-256: 8329bcbadc7f81539a4969ca13f0be5b8eb7652b912324a1926fc9bfb6ec005a
  • SHA-256: be922312978a53c92a49fefd2c9f9cc098767b36f0e4d2e829d24725df65bc21
  • SHA-256: 4243dc8b991f5f8b3c0f233ca2110a1e03a1d716c3f51e88faf1d59b8242d329
  • SHA-256: 7ba47558c99e18c2c6449be804b5e765c48d3a70ceaa04c1e0fae67ff1d7178d
  • SHA-256: 5ef168f83b55d2cbd2426afc5e6fa8161270fa6a2a312831332dc472c95dfa42
  • SHA-256: d3247f03dcd7b9335344ebba76a0b92370f32f1cb0e480c734da52db2bd8df60
  • SHA-256: ed05f5d462767b3986583188000143f0eb24f7d89605523a28950e72e6b9039a
  • SHA-256: 5e55b4caf47a248a10abd009617684e969dbe5c448d087ee8178262aaab68636
  • SHA-256: dcdb9bd39b6014434190a9949dedf633726fdb470e95cc47cdaa47c1964b969f
  • SHA-256: 8d950068f46a04e77ad6637c680cccf5d703a1828fbd6bdca513268af4f2170f
  • SHA-256: 6ed5d50cf9d07db73eaa92c5405f6b1bf670028c602c605dfa7d4fcb80ef0801
  • SHA-256: d1f718d219930e57794bdadf9dda61406294b0759038cef282f7544b44b92285
  • SHA-256: 355b4a82313074999bd8fa1332b1ed00034e63bd2a0d0367e2622f35d75cf140
  • SHA-256: 4226738489c2a67852d51dbf96574f33e44e509bc265b950d495da79bb457400
  • SHA-256: 13fd3ad690c73cf0ad26c6716d4e9d1581b47c22fb7518b1d3bf9cfb8f9e9123
  • SHA-256: 4bf8fbb7db583e1aacbf36c5f740d012c8321f221066cc68107031bd8b6bc1ee
  • SHA-256: 95a922e178075fb771066db4ab1bd70c7016f794709d514ab1c7f11500f016cd
  • SHA-256: a9ca77dfe03ce15004157727bb43ba66f00ceb215362c9b3d199f000edaa8d61
  • SHA-256: 2813b6c07d17d25670163e0f66453b42d2f157bf2e42007806ebc6bb9d114acc
  • SHA-256: 8e43d1ddbd5c129055528a93f1e3fab0ecdf73a8a7ba9713dc4c3e216d7e5db4

  • ThreatDown - Rhysida Using Oyster Backdoor

  • domain: codeforprofessionalusers[.]com

  • SHA-256: 0a7fd836d36ed8e8e9aa7bc41fdc9242333e8469059dec8886b7d935f3651679

  • ip: 173.46.80[.]206


  • ShadowStack - Rhysida Analysis

  • SHA-256: b55ecbddcbed916481ad537807cd3e33cb71814be6ce8e03eb63b629ccb8c692

CVEs Used

  • CISA Cybersecurity Advisory
    • CVE-2020-1472

YARA Rules

  • SentinelOne - Attack on Chilean Army
rule rw_rhysida {
    meta:
        author = "Alex Delamotte"
        description = "Rhysida ransomware detection."
        sample = "69b3d913a3967153d1e91ba1a31ebed839b297ed"
        reference = "https://s1.ai/rhys"
    strings:
        $typo1 = { 63 6D 64 2E 65 78 65 20 2F 63 20 72 65 67 20 64 65 6C 65 74 65 20 22 48 4B 43 55 5C 43 6F 6E 74 74 6F 6C 20 50 61 6E 65 6C 5C 44 65 73 6B 74 6F 70 22 }
        $cmd1 = { 63 6D 64 2E 65 78 65 20 2F 63 20 72 65 67 20 61 64 64 20 22 48 4B 43 55 5C 53 6F 66 74 77 61 72 65 5C 4D 69 63 72 6F 73 6F 66 74 5C 57 69 6E 64 6F 77 73 5C 43 75 72 72 65 6E 74 56 65 72 73 69 6F 6E 5C 50 6F 6C 69 63 69 65 73 5C 41 63 74 69 76 65 44 65 73 6B 74 6F 70 }
        $cmd2 = { 63 6D 64 2E 65 78 65 20 2F 63 20 72 65 67 20 61 64 64 20 22 48 4B 4C 4D 5C 53 6F 66 74 77 61 72 65 5C 4D 69 63 72 6F 73 6F 66 74 5C 57 69 6E 64 6F 77 73 5C 43 75 72 72 65 6E 74 56 65 72 73 69 6F 6E 5C 50 6F 6C 69 63 69 65 73 5C 53 79 73 74 65 6D 22 20 2F 76 20 57 61 6C 6C 70 61 70 65 72 20 2F 74 20 52 45 47 5F 53 5A 20 2F 64 20 22 43 3A 5C 55 73 65 72 73 5C 50 75 62 6C 69 63 5C 62 67 2E 6A 70 67 22 20 2F 66 }
        $byte1 = { 48 8D 05 72 AA 05 00 48 8B 00 8B 95 }
        $byte2 = { 48 8D 15 89 CF 03 00 48 89 C1 E8 F9 1C 03 00 44 }
    condition:
        2 of them
}
  • ShadowStack - Rhysida Analysis
rule RhysidaRansomware {
    meta:
      description = "rule to detect Rhysida Ransomware"
      author = "ShadowStackRe.com"
      date = "2023-12-12"
      Rule_Version = "v1"
      malware_type = "ransomware"
      malware_family = "Rhysida"
      License = "MIT License, https://opensource.org/license/mit/"
    strings:
      $strShadowCopy = " vssadmin.exe Delete Shadows"
      $strRhsyida01 = "Rhysida-0.1"
      $strRhysida = "rhysida"
      $strRegKey1 = "cmd.exe /c reg delete \"HKCU\\Contol Panel\\Desktop"
      $strRegKey2 = "Policies\\ActiveDesktop\" /v NoChangingWallPaper"
      $strRunDll32 = "rundll32.exe user32.dll,UpdatePerUserSystemParameters"
      $strPDF = "CriticalBreachDetected.pdf"
    condition:
      all of them
}
  • diˈtekSHən
rule INDICATOR_KB_ID_Ransomware_Rhysida {
    meta:
        author = "ditekShen"
        description = "Detects files referencing identities associated with Rhysida ransomware"
    strings:
        $s1 = "SethZemlak@onionmail.org" ascii wide nocase
        $s2 = "JacquieKunze@onionmail.org" ascii wide nocase
    condition:
        any of them
}

Sigma Rules:

SigmaHQ Potentially Suspicious Desktop Background Change Via Registry


title: Potentially Suspicious Desktop Background Change Via Registry
id: 85b88e05-dadc-430b-8a9e-53ff1cd30aae
related:
    - id: 8cbc9475-8d05-4e27-9c32-df960716c701
      type: similar
status: test
description: |
    Detects registry value settings that would replace the user's desktop background.
    This is a common technique used by malware to change the desktop background to a ransom note or other image.    
references:
    - https://www.attackiq.com/2023/09/20/emulating-rhysida/
    - https://research.checkpoint.com/2023/the-rhysida-ransomware-activity-analysis-and-ties-to-vice-society/
    - https://www.trendmicro.com/en_us/research/23/h/an-overview-of-the-new-rhysida-ransomware.html
    - https://www.virustotal.com/gui/file/a864282fea5a536510ae86c77ce46f7827687783628e4f2ceb5bf2c41b8cd3c6/behavior
    - https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.WindowsDesktop::Wallpaper
    - https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.ControlPanelDisplay::CPL_Personalization_NoDesktopBackgroundUI
author: Nasreddine Bencherchali (Nextron Systems), Stephen Lincoln @slincoln-aiq (AttackIQ)
date: 2023-12-21
tags:
    - attack.defense-evasion
    - attack.impact
    - attack.t1112
    - attack.t1491.001
logsource:
    product: windows
    category: registry_set
detection:
    selection_keys:
        TargetObject|contains:
            - 'Control Panel\Desktop'
            - 'CurrentVersion\Policies\ActiveDesktop'
            - 'CurrentVersion\Policies\System'
    selection_values_1:
        TargetObject|endswith: 'NoChangingWallpaper'
        Details: 'DWORD (0x00000001)' # Prevent changing desktop background
    selection_values_2:
        TargetObject|endswith: '\Wallpaper'
    selection_values_3:
        TargetObject|endswith: '\WallpaperStyle'
        Details: '2' # Stretch
    filter_main_svchost:
        # Note: Excluding GPO changes
        Image|endswith: '\svchost.exe'
    condition: selection_keys and 1 of selection_values_* and not 1 of filter_main_*
falsepositives:
    - Administrative scripts that change the desktop background to a company logo or other image.
level: medium

References

  • https://www.sentinelone.com/anthology/rhysida/
  • https://fourcore.io/blogs/rhysida-ransomware-history-ttp-adversary-emulation
  • https://blog.talosintelligence.com/rhysida-ransomware/
  • https://www.securitylab.ru/news/543724.php
  • https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-319a
  • https://detect.fyi/rhysida-ransomware-and-the-detection-opportunities-3599e9a02bb2
  • https://www.sentinelone.com/blog/rhysida-ransomware-raas-crawls-out-of-crimeware-undergrowth-to-attack-chilean-army/
  • https://www.cronup.com/ejercito-de-chile-es-atacado-por-la-nueva-banda-de-ransomware-rhysida/
  • https://xakep.ru/2023/11/21/rhysida-british-library/
  • https://www.esentire.com/blog/rhysida-ransomware-group-turns-its-wrath-warns-esentire
  • https://www.threatdown.com/blog/rhysida-using-oyster-backdoor-to-deliver-ransomware/
  • https://www.bankinfosecurity.com/rhysida-threats-a-26516
  • https://www.shadowstackre.com/analysis/rhysida
  • https://www.trendmicro.com/en_us/research/23/h/an-overview-of-the-new-rhysida-ransomware.html
  • https://www.helpnetsecurity.com/2023/11/28/slovenian-power-company-ransomware/
  • https://www.logpoint.com/wp-content/uploads/2023/12/logpoint-etpr-rhysida.pdf
  • https://www.orangecyberdefense.com/de/blog/threat/rhysida-ransomware-und-die-erkennungsmoeglichkeiten