# Rhysida

> As of 2026-09-06, Rhysida is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning ransomware, malware. Also known as Vanilla Tempest. ATT&CK coverage spans 46 techniques across 13 tactics in 3 of 3 tracked threats. Most-observed techniques: T1003.003 (NTDS), T1021.001 (Remote Desktop Protocol), T1053.005 (Scheduled Task).

- **Nation:** Russia
- **Tracked threats:** 3
- **Categories:** RANSOMWARE, MALWARE
- **Also known as:** Vanilla Tempest
- **As of:** 2026-09-06

## ATT&CK techniques observed

46 techniques observed across 3 of 3 tracked threats. Tactics: Command and Control (9), Discovery (8), Stealth (formerly Defense Evasion) (7), Execution (5), Defense Impairment (3), Initial Access (3).

- [T1003.003](https://intel.threadlinqs.com/technique/T1003.003) NTDS — Credential Access — observed in 2 of 3 tracked threats
- [T1021.001](https://intel.threadlinqs.com/technique/T1021.001) Remote Desktop Protocol — Lateral Movement — observed in 2 of 3 tracked threats
- [T1053.005](https://intel.threadlinqs.com/technique/T1053.005) Scheduled Task — Persistence — observed in 2 of 3 tracked threats
- [T1059.001](https://intel.threadlinqs.com/technique/T1059.001) PowerShell — Execution — observed in 2 of 3 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 2 of 3 tracked threats
- [T1219](https://intel.threadlinqs.com/technique/T1219) Remote Access Tools — Command and Control — observed in 2 of 3 tracked threats
- [T1490](https://intel.threadlinqs.com/technique/T1490) Inhibit System Recovery — Impact — observed in 2 of 3 tracked threats
- [T1001](https://intel.threadlinqs.com/technique/T1001) Data Obfuscation — Command and Control — observed in 1 of 3 tracked threats
- [T1018](https://intel.threadlinqs.com/technique/T1018) Remote System Discovery — Discovery — observed in 1 of 3 tracked threats
- [T1021.002](https://intel.threadlinqs.com/technique/T1021.002) SMB/Windows Admin Shares — Lateral Movement — observed in 1 of 3 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 1 of 3 tracked threats
- [T1053](https://intel.threadlinqs.com/technique/T1053) Scheduled Task/Job — Persistence — observed in 1 of 3 tracked threats
- [T1055.002](https://attack.mitre.org/techniques/T1055/002/) Process Injection: Portable Executable Injection — Privilege Escalation — observed in 1 of 3 tracked threats
- [T1057](https://intel.threadlinqs.com/technique/T1057) Process Discovery — Discovery — observed in 1 of 3 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 1 of 3 tracked threats

## Tracked threats

- [Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)](https://intel.threadlinqs.com/threat/TL-2026-2357) — CRITICAL
- [Rhysida Ransomware Claims Berlin State Government Breach Ahead of September Election](https://intel.threadlinqs.com/threat/TL-2026-2206) — HIGH
- [SystemBC (Coroxy) Malware: Tor-Based SOCKS5 Proxy Backdoor Enabling Ransomware Persistence and C2 Obfuscation](https://intel.threadlinqs.com/threat/TL-2026-1005) — CRITICAL

## Related CVEs

1 CVE referenced by tracked Rhysida activity.

- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Rhysida
