Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)
Rhysida Ransomware Campaign Targeting German Public (TL-2026-2357) is a critical-severity ransomware operation, first published 2026-09-06. It is attributed to Rhysida (Russia) with medium confidence, affects Microsoft Windows Server, references 1 CVE (CVE-2020-1472), maps to 22 MITRE ATT&CK techniques (T1003.003, T1018, T1021.001), and is covered by 9 detection rules and 37 indicators of compromise.
Key facts for TL-2026-2357
- Threat ID
- TL-2026-2357
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-09-06
- Last reviewed
- 2026-09-06
- Attribution
- Rhysida
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- government administration, education, health, manufacturing, technology
- Target regions
- Europe, North America, Middle East, 005 - South America, australia
- Detection rules
- 9
- Indicators of compromise
- 37
Malware and tooling in Rhysida Ransomware Campaign Targeting German Public
Malware and tooling: AnyDesk, rhysida
Rhysida ransomware, deployed by the Vanilla Tempest access crew (formerly Vice Society/Storm-0832), targeted German state capitals in 2026. Stuttgart was listed on the Rhysida leak site in May 2026 with a 5 BTC demand. In August, a major breach of Berlin state agencies exfiltrated 5.79 TB of data (~1.44 million files) including classified government material, critical-infrastructure security assessments for Berlin's water supply, CBRN threat planning documents, national defense plans, 3,226 NDAs, 148 IBANs, plaintext credentials, and personal data on 12,076 individuals. Berlin refused the 30 BTC ransom (~€2M); the data was published on the dark web on September 4-5, 2026, 15 days before the Berlin state election.
How Rhysida Ransomware Campaign Targeting German Public works
Rhysida ransomware, active since May 2023 as a ransomware-as-a-service (RaaS) operation, has conducted a sustained campaign against German public administration in 2026. The threat involves a sophisticated multi-stage infection chain orchestrated by the Vanilla Tempest threat cluster (formerly tracked by Microsoft as Storm-0832/DEV-0832, also known as Vice Society), who serve as an access and deployment crew. The infection chain begins with malvertising and search-engine optimization (SEO) poisoning — users searching for trusted software (Microsoft Teams, PuTTY, Zoom, WinSCP, AutoDesk, Google Authenticator) are redirected to fraudulent download pages hosting trojanized, fraudulently-signed installers. These installers deploy the Endico downloader (protected by the Tomb crypter), which retrieves the Broomstick/Oyster backdoor, followed by Vidar infostealer and/or the Supper backdoor for persistent post-compromise access. Hands-on-keyboard operators then conduct extensive Active Directory discovery using native Windows tools (PowerShell, nltest, net commands, systeminfo, ipconfig) before deploying the Rhysida ransomware payload. The code-signing infrastructure was enabled by Fox Tempest, a malware-signing-as-a-service operation Microsoft disrupted in May 2026, which created over 1,000 fraudulent certificates using Azure Artifact Signing infrastructure. Fox Tempest activity was observed immediately before Stuttgart appeared on the Rhysida leak site on May 19, 2026. The Berlin intrusion involved data exfiltration between August 7-12, 2026 from the Senate administration network. Affected departments were disconnected on August 14 after discovery. The exfiltrated data is extraordinary in scope: 5.79 TB comprising 1,439,893 files spanning mapping/geodata (124,823 files), legal/complaints (77,939), financial records (55,553), contracts (46,522), HR files (27,299), confidential documents (11,777), infrastructure assessments (8,110), password-containing files (5,941), health records (2,738), and contact files (2,287). Critically, the cache included CBRN (Chemical, Biological, Radiological, Nuclear) threat planning documents, Berlin water supply vulnerability assessments, LKA (State Criminal Police) investigation files, national defense plans including federal emergency communication channels, Bundesrat committee records, classified-material handling documentation, SQL database dumps spanning 2020-2026, passport/ID scans, and payroll data. The Berlin government led by Mayor Kai Wegner and Interior Senator Iris Spranger refused the ransom, stating the state of Berlin does not submit to extortion. Multiple task forces were activated including the State Criminal Police, public prosecutor's office, and federal security agencies. The stolen data was published on the dark web on September 4-5, 2026 after the ransom deadline expired. The breach occurred 15 days before Berlin's House of Representatives election (September 20, 2026); while election infrastructure was confirmed uncompromised, the BSI warned of potential hack-and-leak operations. Rhysida has claimed approximately 280-295+ victims globally since 2023, primarily targeting education (~35%), healthcare, government, manufacturing, and technology sectors. Notable prior victims include the Chilean Army (May 2023, ~360,000 documents leaked), Prospect Medical Holdings (August 2023, 16+ hospitals, 1.3M+ affected), the British Library (October 2023, ~600GB data exfiltrated), and Lurie Children's Hospital (January 2024, ~776,000 affected).
MITRE ATT&CK techniques used in TL-2026-2357
Credential Access
T1003.003 OS Credential Dumping: NTDS
Discovery
T1018 Remote System Discovery; T1069.002 Permission Groups Discovery: Domain Groups; T1087.002 Account Discovery: Domain Account; T1482 Domain Trust Discovery
Lateral Movement
T1021.001 Remote Services: Remote Desktop Protocol; T1570 Lateral Tool Transfer
Defense Evasion
Persistence
T1053.005 Scheduled Task/Job: Scheduled Task
Privilege Escalation
T1055.002 Process Injection: Portable Executable Injection
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1059.009 Command and Scripting Interpreter: Cloud API
Initial Access
command-and-control
Impact
T1490 Inhibit System Recovery; T1657 Financial Theft
Collection
defense-impairment
T1553.002 Subvert Trust Controls: Code Signing; T1685.005 Clear Windows Event Logs
Command and Control
Resource Development
Affected products and versions in Rhysida Ransomware Campaign Targeting German Public
- Microsoft — Windows Server
Vulnerable versions: 2008; 2012; 2016; 2019; 2022
Fixed in: Patched versions post-August 2020 (KB4565349+) - Microsoft — Azure Trusted Signing
Vulnerable versions: Pre-May 2026 infrastructure (Fox Tempest abuse)
Fixed in: Post-May 2026 with revocation of 1,000+ fraudulent certificates
Remediation for Rhysida Ransomware Campaign Targeting German Public
Patches
- Apply all Patch Tuesday updates prioritizing CVE-2020-1472 (Zerologon) and other KEV-listed vulns
- Update PowerShell to version 5.0+ for adequate logging capability
- Ensure all VPN appliances and remote access gateways are fully patched
Immediate actions
- Isolate affected systems and disconnect compromised network segments
- Revoke all exposed credentials and force password reset for all domain accounts
- Block known C2 infrastructure IPs and domains at perimeter
- Enable enhanced PowerShell logging and command-line process auditing across all endpoints
- Deploy EDR detection rules for the AlphaSecurity scheduled task and Rhysida encryption artifacts
Workarounds
- Apply application controls to prevent unauthorized remote access software (AnyDesk, etc.)
- Restrict RDP to jump-box systems with MFA enforcement
- Disable command-line/scripting permissions where operationally feasible
- Add email banners for external communications and disable hyperlinks in received emails
Longer-term hardening
- Implement phishing-resistant MFA for all remote access (VPN, webmail, critical systems)
- Deploy network segmentation to contain lateral movement
- Restrict PowerShell execution to case-by-case basis via Group Policy
- Implement application allowlisting for remote access tools
- Deploy offline, encrypted, immutable backups with daily-to-weekly restoration testing
- Establish continuous monitoring for AZCopy/StorageExplorer usage as exfiltration indicator
- Implement Just-in-Time (JIT) privileged access management
CVEs associated with Rhysida Ransomware Campaign Targeting German Public
Timeline of Rhysida Ransomware Campaign Targeting German Public
- Rhysida ransomware first observed in the wild; Chilean Army attack with ~360,000 documents leaked marks one of the most consequential military ransomware attacks on record
- Rhysida attacks British Library, exfiltrating ~600 GB of data (490,000+ files); library refuses £600K ransom; operational disruption lasted months
- Vanilla Tempest threat cluster begins using Fox Tempest malware-signing-as-a-service to fraudulently sign trojanized Microsoft Teams installers and Oyster backdoor payloads
- Microsoft detects the fake Teams campaign and revokes over 200 fraudulent code-signing certificates issued through Azure Trusted Signing, SSL.com, DigiCert, and GlobalSign
- Supper backdoor C2 infrastructure observed heavily active across multiple IPs (185.233.166.26, 194.61.120.130, 37.72.168.146, 38.134.148.147, 51.222.96.58, 95.169.180.113) indicating sustained post-compromise access across multiple victims
- Microsoft publishes Fox Tempest investigation — malware-signing-as-a-service operation created over 1,000 certificates and hundreds of Azure tenants/subscriptions abusing Artifact Signing infrastructure; supply-side takedown executed
- City of Stuttgart appears on Rhysida data-leak site with a 5 BTC ransom demand; Stuttgart initially states it has no evidence confirming a cyber incident
- Data exfiltration begins from Berlin state administration network; attackers exfiltrate 5.79 TB over a 6-day window spanning August 7-12
- Berlin affected Senate departments disconnected from the state network upon discovery of the intrusion; forensic investigations subsequently uncover additional data loss
- Rhysida gang publicly claims responsibility for the Berlin attack, listing the city on their leak site with a 30 BTC (~€2M) ransom demand and countdown timer
- Berlin city administration confirms data theft; Mayor Kai Wegner states 'The state of Berlin is being blackmailed' and refuses to pay ransom; Interior Senator Iris Spranger confirms election infrastructure secure
- Rhysida publishes stolen Berlin data on the dark web after ransom deadline expires; 1,439,893 files (~6 TB) including CBRN threat planning, national defense plans, LKA investigation documents, water supply assessments, classified government material, and personal data published
- Berlin state election for the House of Representatives scheduled; hack-and-leak concerns raised by BSI; election infrastructure confirmed uncompromised but data leak creates significant political crisis
Sources cited for Rhysida Ransomware Campaign Targeting German Public
- Rhysida in Germany — From an Early Ransomware Payload to the 2026 Stuttgart and Berlin Threat
- Berlin confirms data theft after Rhysida ransomware attack claims
- StopRansomware: Rhysida Ransomware (AA23-319A)
- Berlin city government says it won't submit to extortion after pre-election cyberattack
- Berlin launches crisis response after hackers publish stolen data
- Berlin cyberattack: Hackers leak highly sensitive data across dark web
- Berlin data breach: Rhysida ransomware attack explained
- Microsoft investigates Fox Tempest malware-signing-as-a-service
- IBM X-Force: Vanilla Tempest threat analysis
- CISA Known Exploited Vulnerabilities Catalog
- Fortinet: Analyzing Rhysida Ransomware Intrusion
- CybelAngel: Rhysida Ransomware — TTPs, IOCs and Defence in 2026
- Ransomware.live: Rhysida Leak Site Tracker
- Berlin election infrastructure secure, says Interior Senator Spranger
More in ransomware
- Magniber Ransomware: Rewritten 2022 Variant Uses MSI Installer, AES-NI Encryption, and UAC Bypass
- Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint Defenses
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec References
- Vexy Ransomware hits Mega Velocity — 46.68 GB exfiltrated, double extortion
- Vexy Ransomware (RaaS) claims Sancity (sancity.in) — Indian real estate/construction group; 130 MB data exfiltration alleged
Detection coverage for TL-2026-2357
As of 2026-09-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2357 across Splunk SPL, Microsoft KQL and Sigma, covering 37 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2357
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.