• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
new report exposes vice society's collaboration with rhysida ransomware

New Report Exposes Vice Society’s Collaboration with Rhysida Ransomware

You are here: Home / General Cyber Security News / New Report Exposes Vice Society’s Collaboration with Rhysida Ransomware
August 9, 2023

Tactical similarities have been unearthed between the double extortion ransomware group identified as Rhysida and Vice Modern society, which include in their concentrating on of education and learning and healthcare sectors.

“As Vice Society was noticed deploying a selection of commodity ransomware payloads, this website link does not propose that Rhysida is completely utilized by Vice Modern society, but demonstrates with at minimum medium self-confidence that Vice Culture operators are now utilizing Rhysida ransomware,” Look at Position mentioned in a new report.

Vice Society, tracked by Microsoft less than the name Storm-0832, has a pattern of utilizing currently present ransomware binaries that are marketed on prison message boards to pull off their attacks. The monetarily enthusiastic gang has also been noticed resorting to pure extortion-themed attacks whereby the info is exfiltrated without encrypting them.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Cybersecurity

First noticed in May well 2023, the Rhysida ransomware team is recognised to rely on phishing attacks and Cobalt Strike to breach targets’ networks and deploy their payloads. A the vast majority of its victims are centered in the U.S., the U.K., Italy, Spain, and Austria.

Lateral motion is facilitated utilizing distant desktop protocol (RDP) and distant PowerShell classes, when the ransomware payload is deployed employing PsExec. Command-and-management is obtained by suggests of backdoors like SystemBC and remote administration applications these as AnyDesk.

Rhysida Ransomware

The attack chains are also notable for persistently erasing logs and forensic artifacts to include their path and initiating a domain-large password modify to inhibit remediation initiatives.

“They principally attack schooling, federal government, manufacturing, and technology and managed provider company sectors nonetheless, there have been modern attacks against the Healthcare and General public Overall health (HPH) sector,” the U.S. Division of Health and fitness and Human Services’ Overall health Sector Cybersecurity Coordination Heart explained in an notify final week.

The most current results from the Israeli cybersecurity business have revealed a “distinct correlation” involving the emergence of Rhysida and the disappearance of Vice Culture.

Cybersecurity

This contains the use of NTDSUtil, the creation of community firewall policies to allow C2 communications by using SystemBC, and the utilization of a commodity device identified as PortStarter, which has been linked practically completely to Vice Society.

“At any time because Rhysida first appeared, Vice Modern society has only released two victims,” Check Stage said. “It is probable that all those had been performed previously and ended up only printed in June. Vice Modern society actors stopped posting on their leak site given that June 21, 2023.”

The other important indicator is the commonality in their victimology footprints. Both of those Rhysida and Vice Society have disproportionately qualified the training vertical, accounting for 32% and 35% of the over-all distribution, respectively.

“Our analysis of Rhysida ransomware intrusions reveals very clear ties concerning the team and the notorious Vice Modern society, but it also reveals a grim truth of the matter – the TTPs of prolific ransomware actors remain mostly unchanged,” the firm stated.

“From the usage of distant administration applications these as AnyDesk to the deployment of ransomware via PsExec, danger actors leverage a selection of instruments to facilitate these attacks.”

Uncovered this posting intriguing? Adhere to us on Twitter  and LinkedIn to read extra exceptional information we publish.


Some pieces of this short article are sourced from:
thehackernews.com

Previous Post: «qakbot malware operators expand c2 network with 15 new servers QakBot Malware Operators Expand C2 Network with 15 New Servers
Next Post: Microsoft Releases Patches for 74 New Vulnerabilities in August Update microsoft releases patches for 74 new vulnerabilities in august update»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]
  • GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infections

Copyright © TheCyberSecurity.News, All Rights Reserved.