Japan

rhysida

Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks and Cobalt Strike to breach the targets' networks and deploy their payloads.<br> <br> The group threatens to publicly distribute exfiltrated data if the ransom is not paid, and it's worth mentioning that Rhysida is still in the early stages of development.<br> <br> The ransomware leaves PDF notes in the affected folders, instructing…

First seen 2023-06-05 · Last seen 2026-09-08 · 3 Japan claims

Tactics: Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Discovery, Collection, Exfiltration, Command and Control, Impact, Resource Development, Reconnaissance

CVEs named by the source: CVE-2026-50751, CVE-2026-48027, CVE-2023-21529, CVE-2024-1708, CVE-2025-60710

Cached from ransomware.live. 2026-10-01 PT. Leak sites are not linked.

YOKOSUKA GAKUIN

JP

Discovered: 2025-12-16 <span class="ransom-ago">(9mo ago)</span>

YOKOSUKA GAKUIN

yokosuka-gakuin.ac.jp

Furuno Electric

JP

Discovered: 2025-10-13 <span class="ransom-ago">(11mo ago)</span>

Furuno Electric FURUNO strives to contribute to realisation of the pleasant society filled with safety and peace of mind by giving…

furuno.com

Microworks

JP

Discovered: 2024-10-15 <span class="ransom-ago">(23mo ago)</span>

Microworks Microworks Point of Sale Prism offers an ideal computer system for pizza delivery, restaurant management, and franchise food…

microworks.com