← Back to Daily Briefing (#Rhysida)

The Rhysida ransomware has evolved into the "Vanilla Tempest" ecosystem, utilizing "Fox Tempest" malware-signing-as-a-service to bypass trust models via fraudulently obtained certificates. In August 2026, the Berlin state administration suffered a confirmed breach resulting in the exfiltration of 5.79 TB of data (~1.44 million files) and a 30 BTC ransom demand. The attack chain leveraged trojanized software, such as fake MS Teams installers, and rapid Active Directory reconnaissance using nltest and DirectorySearcher. This operation demonstrates a shift toward prolonged persistence and massive data theft, necessitating a defense strategy focused on upstream behavioral detection rather than static binary signatures.

  • Incident Overview: Berlin and Stuttgart 2026

    • Confirmed compromise of the Berlin state administration in August 2026, specifically impacting the Senate Department for Mobility, Transport, Climate Protection and Environment.
    • Massive data exfiltration occurred between August 7 and 12, totaling 5.79 Terabytes of sensitive files.
    • Threat actors demanded 30 BTC (approximately $2 million), which the Berlin government officially refused to pay.
    • A prior, unconfirmed extortion claim against the city of Stuttgart was recorded in May 2026 with a lower demand of 5 BTC.
  • Attack Vector and Campaign Mechanics

    • Integration of "Fox Tempest," a signing-as-a-service operation via signspace(.)cloud, to bypass security software using fraudulent certificates.
    • Initial access achieved through malvertising and trojanized applications, specifically fraudulent Microsoft Teams installations via microsoft-teams(.)icu.
    • Persistence established through the creation of a scheduled task named "AlphaSecurity."
    • Rapid internal reconnaissance utilizing nltest /dclist, nltest /trusted_domains, and PowerShell DirectoryServices.DirectorySearcher to map Active Directory.
  • Technical Payload Analysis

    • Encryption utilizes AES-256-CTR with RSA-4096 OAEP, employing ChaCha20 as the Pseudo-Random Number Generator (PRNG).
    • Deployment of a modular toolkit including the Rhysida ransomware, Vidar infostealer, and the "Supper" backdoor.
    • Identifiable file artifacts include the .rhysida file extension and a CriticalBreachDetected.pdf ransom note.
    • C2 infrastructure utilizes various ports (80, 8080, 1080, 4043) across IPs such as 213.232.236(.)211 and 151.241.99(.)169.
  • Indicators of Compromise (IoCs) and Defense

    • High-confidence hashes: 67a78b39e760e3460a135a7e4fa096ab6ce6b013658103890c866d9401928ba5 (Rhysida) and 604f7aa77a14f07baa21e76b73ceb7970037bfbdcc2040bf2e445702e99587a0 (Supper).
    • Malicious domains for blocking: scs-techresources(.)com, coretether(.)com, nucleusgate(.)com, and registrywave(.)com.
    • Defense strategy shift: Transition from detecting final ransomware binaries to monitoring for administrative command bursts and suspicious certificate provenance.
    • Implementation of strict auditing for nltest execution and unauthorized PowerShell directory queries.
  • Conclusion and Strategic Outlook

    • The transition to Vanilla Tempest marks a move toward modular, outsourced cybercrime ecosystems that scale via "Trust-as-a-Service."
    • The Berlin incident underscores the high risk of "encryption-last" strategies where exfiltration is the primary leverage for extortion.
    • Organizations must move beyond signature-based detection to identify the behavioral markers of the Vanilla Tempest infection chain.

Related posts

  1. Malware News — Rhysida in Germany - From an Early Ransomware Payload to the 2026 Stuttgart and Berlin Threat…
  2. thehackernews.com — Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
  3. cybelangel.com — Rhysida Ransomware Explained: TTPs, IOCs and How to Defend in 2026
  4. Threatmon
  5. Safestate
  6. Aa
  7. Berlin
  8. Ebuildersecurity
  9. SecurityWeek — Berlin Won’t Pay Extortion Group Claiming Data Theft

LINK COPIED TO CLIPBOARD