Rhysida in Germany - From an Early Ransomware Payload to the 2026 Stuttgart and Berlin Threat…
ID: fddd73d7-ed8b-57b4-bf94-952126f4c047
STIX ID: report--fddd73d7-ed8b-57b4-bf94-952126f4c047
Feed Name: Detect FYI
This report analyzes the Rhysida (Vanilla Tempest) ransomware ecosystem active in 2026, linking malvertising, trojanized installers, fraudulent code-signing (Fox Tempest), and a chain of loaders/backdoors (Endico, Broomstick/Oyster, Supper, Vidar) that led to extortion claims in Stuttgart and confirmed data exfiltration from Berlin state administration; it provides sample hashes, C2/IP indicators, ATT&CK-aligned TTPs, and prioritized detection and hunting opportunities focused on upstream behaviors before encryption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
