logo

Rhysida in Germany - From an Early Ransomware Payload to the 2026 Stuttgart and Berlin Threat…

ID: fddd73d7-ed8b-57b4-bf94-952126f4c047

STIX ID: report--fddd73d7-ed8b-57b4-bf94-952126f4c047

Feed Name: Detect FYI

Threat Score
78/100

Date Published: 2026-09-05

Date Updated: 2026-09-10

Author: SIMKRA

...
...

This report analyzes the Rhysida (Vanilla Tempest) ransomware ecosystem active in 2026, linking malvertising, trojanized installers, fraudulent code-signing (Fox Tempest), and a chain of loaders/backdoors (Endico, Broomstick/Oyster, Supper, Vidar) that led to extortion claims in Stuttgart and confirmed data exfiltration from Berlin state administration; it provides sample hashes, C2/IP indicators, ATT&CK-aligned TTPs, and prioritized detection and hunting opportunities focused on upstream behaviors before encryption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.