➤Summary
Ransomware attacks have been on the rise in recent years, and two new groups have emerged in May 2023: Rhysida and DarkRace. These sophisticated ransomware groups have already targeted several organizations across Europe, encrypting victims’ data and demanding ransom payments.
Rhysida first appeared in late May 2023 and has attacked at least four known victims, according to posts on their dark web blog. Targets include:
The group positions themselves as a “cybersecurity team” who are doing their victims a favor by targeting their systems and highlighting the supposed potential ramifications of the involved security issues.
To carry out their attacks, Rhysida uses advanced techniques like social engineering and exploit kits to gain access to victims’ systems. Once inside, they deploy strong encryption to lock down data and demand ransom payments in exchange for the decryption key.
DarkRace is another ransomware group that emerged in late May 2023. It works by encrypting files on infected systems and leaving ransom notes with instructions for paying a ransom to recover the files. In comparison to many ransomware gangs that use unanimous extensions to encrypt files, like Rhysida – “.rhysida”, DarkRace stands apart. This malware encrypts files and appends its extension to filenames “.1352FF327”, the text file containing a ransom note looks like “Readme.1352FF327.txt”.
At the moment of writing this article, the group has targeted at least six known victims, according to their darknet blog:
DarkRace is known to be distributed through infected email attachments (macros), torrent websites, malicious ads among other methods.
To protect against ransomware attacks like those carried out by Rhysida and DarkRace, organizations should implement a multi-layered cybersecurity strategy:
Stay up-to-date on the latest ransomware threats, techniques, and best practices. Ransomware groups are constantly evolving their methods.
By making a comprehensive approach to security a priority, organizations can reduce the risk of becoming victims of ransomware attacks. But they must remain vigilant, as new groups like Rhysida and DarkRace emerge to threaten businesses and critical infrastructure. With strong defenses and proactive security strategies in place, the impact of any attack can at least be minimized.
If you liked this article, we advise you to read our previous article about the rise of AI malware. Follow us on Twitter and LinkedIn for more content.
Your data might already be exposed. Most companies find out too late. Let ’s change that. Trusted by 100+ security teams.
🚀Ask for a demo NOW →