FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Rhysida and Vanilla Tempest: Sophisticated Ransomware Ecosystem Targets German State Administration

The Rhysida ransomware has evolved into the "Vanilla Tempest" ecosystem, utilizing "Fox Tempest" malware-signing-as-a-service to bypass trust models via fraudulently obtained certificates. In August 2026, the Berlin state administration suffered a confirmed breach resulting in the exfiltration of 5.79 TB of data (~1.44 million files) and a 30 BTC ransom demand. The attack chain leveraged trojanized software, such as fake MS Teams installers, and rapid Active Directory reconnaissance using nltest and DirectorySearcher. This operation demonstrates a shift toward prolonged persistence and massive data theft, necessitating a defense strategy focused on upstream behavioral detection rather than static binary signatures.


LINK COPIED TO CLIPBOARD