The Rhysida ransomware has evolved into the "Vanilla Tempest" ecosystem, utilizing "Fox Tempest" malware-signing-as-a-service to bypass trust models via fraudulently obtained certificates. In August 2026, the Berlin state administration suffered a confirmed breach resulting in the exfiltration of 5.79 TB of data (~1.44 million files) and a 30 BTC ransom demand. The attack chain leveraged trojanized software, such as fake MS Teams installers, and rapid Active Directory reconnaissance using nltest and DirectorySearcher. This operation demonstrates a shift toward prolonged persistence and massive data theft, necessitating a defense strategy focused on upstream behavioral detection rather than static binary signatures.
-
Incident Overview: Berlin and Stuttgart 2026
- Confirmed compromise of the Berlin state administration in August 2026, specifically impacting the Senate Department for Mobility, Transport, Climate Protection and Environment.
- Massive data exfiltration occurred between August 7 and 12, totaling 5.79 Terabytes of sensitive files.
- Threat actors demanded 30 BTC (approximately $2 million), which the Berlin government officially refused to pay.
- A prior, unconfirmed extortion claim against the city of Stuttgart was recorded in May 2026 with a lower demand of 5 BTC.
-
Attack Vector and Campaign Mechanics
- Integration of "Fox Tempest," a signing-as-a-service operation via
signspace(.)cloud, to bypass security software using fraudulent certificates. - Initial access achieved through malvertising and trojanized applications, specifically fraudulent Microsoft Teams installations via
microsoft-teams(.)icu. - Persistence established through the creation of a scheduled task named "AlphaSecurity."
- Rapid internal reconnaissance utilizing
nltest /dclist,nltest /trusted_domains, and PowerShellDirectoryServices.DirectorySearcherto map Active Directory.
- Integration of "Fox Tempest," a signing-as-a-service operation via
-
Technical Payload Analysis
- Encryption utilizes AES-256-CTR with RSA-4096 OAEP, employing ChaCha20 as the Pseudo-Random Number Generator (PRNG).
- Deployment of a modular toolkit including the Rhysida ransomware, Vidar infostealer, and the "Supper" backdoor.
- Identifiable file artifacts include the
.rhysidafile extension and aCriticalBreachDetected.pdfransom note. - C2 infrastructure utilizes various ports (80, 8080, 1080, 4043) across IPs such as
213.232.236(.)211and151.241.99(.)169.
-
Indicators of Compromise (IoCs) and Defense
- High-confidence hashes:
67a78b39e760e3460a135a7e4fa096ab6ce6b013658103890c866d9401928ba5(Rhysida) and604f7aa77a14f07baa21e76b73ceb7970037bfbdcc2040bf2e445702e99587a0(Supper). - Malicious domains for blocking:
scs-techresources(.)com,coretether(.)com,nucleusgate(.)com, andregistrywave(.)com. - Defense strategy shift: Transition from detecting final ransomware binaries to monitoring for administrative command bursts and suspicious certificate provenance.
- Implementation of strict auditing for
nltestexecution and unauthorized PowerShell directory queries.
- High-confidence hashes:
-
Conclusion and Strategic Outlook
- The transition to Vanilla Tempest marks a move toward modular, outsourced cybercrime ecosystems that scale via "Trust-as-a-Service."
- The Berlin incident underscores the high risk of "encryption-last" strategies where exfiltration is the primary leverage for extortion.
- Organizations must move beyond signature-based detection to identify the behavioral markers of the Vanilla Tempest infection chain.
Related posts
- Malware News — Rhysida in Germany - From an Early Ransomware Payload to the 2026 Stuttgart and Berlin Threat…
- thehackernews.com — Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
- cybelangel.com — Rhysida Ransomware Explained: TTPs, IOCs and How to Defend in 2026
- Threatmon
- Safestate
- Aa
- Berlin
- Ebuildersecurity
- SecurityWeek — Berlin Won’t Pay Extortion Group Claiming Data Theft