🌐Rhysida
🌐 Rhysida is a tracked threat actor in the Clankerusecase corpus. Attributed to ??. Primary motivation: Criminal. We map 9 detection use cases to this actor across 14 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-08-10 to 2026-08-10.
crit 1
9Use cases
1Articles
14Techniques
0IOCs
Known aliases
Rhysida
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1005 · Data from Local SystemT1021.002 · SMB/Windows Admin SharesT1071.001 · Web ProtocolsT1071.004 · DNST1176 · Software ExtensionsT1486 · Data Encrypted for ImpactT1539 · Steal Web Session CookieT1555.003 · Credentials from Web BrowsersT1569.002 · Service Execution
Detection use cases (9)
Beaconing — periodic outbound to small set of destinations Suspicious browser extension installation Infostealer — non-browser process accessing browser cookie/login DBs Crypto-wallet file/keystore access by non-wallet process Asset exposure — vulnerability matches article CVE(s) Ransomware-style mass file rename / extension change LSASS process access / dump (credential theft) Remote service execution — PsExec / SMB lateral movement Trusted vendor binary / installer launching unusual childrenThreat-intel articles (1)
Tracked indicators
CVEs (3)
CVE-2026-33825 CVE-2026-50751 CVE-2026-50752