Malware
Rhysida
- First Reported
- Sep 3, 2026
- Latest Reported
- Sep 30, 2026
Reported Context (2)
- Tempest, DEV-0832, VICE SPIDER, and Vice Society). This group has been linked to the Vice Society and Rhysida ransomware families. The tooling, infrastructure, and shift in delivery mechanisms that Sophos analysts TerminalFix Lures and Lorem Ipsum Loader Deploy a Covert Tunneling Implant
- has been publicly linked to attacks involving multiple ransomware families, including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo. Attackers Revive Node.js Abuse to Run Malware and Maintain Persistence
Malware (13)
Threat Actors (7)
MITRE ATT&CK (13)
Vendors (2)
Products (6)
Tools (3)
Industries (8)
Countries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.