Threat Intelligence Tarot
Vol. II · 101
Criminal (suspected Eastern European)
★★★★★
risk 3/5
✦ The Centipede ✦
Rhysida
Vice Society affiliate
HealthcareEducationGovernmentManufacturingDefense
Active since May 2023 · Financial extortion, Ransomware-as-a-Service
The Centipede moves on many legs through institutional networks, each appendage probing a different system. It has no loyalty to target type: libraries, hospitals, and armies fall with equal indifference.
Tactics & Techniques
RCN
RDV
INI
EXC
PRS
PRV
EVA
CRD
DSC
LAT
COL
C2
EXF
IMP
Notable Operations
- ◆British Library attack (2023, months-long disruption to national services)
- ◆Chilean Army breach with military data published
- ◆Lurie Children's Hospital Chicago (2024, pediatric care disrupted)
- ◆Insomniac Games data leak including Sony acquisition documents
Defenses
- ▸Immutable backups with air-gap separation tested monthly for restorationCIS Control 11 ↗
- ▸RDP access restricted behind VPN with MFA, not internet-exposedCIS Control 6 ↗
- ▸PowerShell logging and constrained language mode enforcementCIS Control 8 ↗
- ▸Sector-specific incident response retainer for healthcare and educationNIST CSF: RC.RP ↗
Reversed: Their Weakness
Security researchers discovered Rhysida's encryption implementation had a flaw enabling decryption without paying ransom. Rapid incident response and offline backup restoration have repeatedly neutralized its leverage.
Share this adversary profile
Compare →swipe to browse
Related Adversaries
Data sourced from MITRE ATT&CK. For educational purposes.