joshhighet / ransomwatch

the transparent ransomware claim tracker 🥷🏼🧅🖥️
https://ransomwatch.telemetry.ltd
The Unlicense
904 stars 135 forks source link

new group: Rhysida #66

Closed yoryio closed 9 months ago

yoryio commented 1 year ago

host location

rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion

group name

Rhysida

group information

New ransomware group spotted in the Dark Web. This group doesn't list their victims in their website.

host

v3 (onion)

parser

No response

yoryio commented 1 year ago

The ransomware group is currently posting some victims and leaks.

JMousqueton commented 1 year ago

Here is the url for the leaks : http://rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion/archive.php

and the parser :

grep "m-2 h4" source/rhysida-* | cut -d '>' -f 3 | cut -d '<' -f 1

nuke86 commented 1 year ago

This address is also to be considered among the additions: http://rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion/archive.php?auction

with the same parser