{"id":13331,"date":"2025-02-28T09:00:22","date_gmt":"2025-02-28T17:00:22","guid":{"rendered":"https:\/\/legacy.gosecure.ai\/?p=13331"},"modified":"2025-03-21T10:29:08","modified_gmt":"2025-03-21T17:29:08","slug":"threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning","status":"publish","type":"post","link":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/","title":{"rendered":"Threat Hunt of the Month: Rhysida Ransomware Group Targeting VPNs and Search Engine Poisoning"},"content":{"rendered":"<p><span data-contrast=\"auto\"><img class=\"size-medium wp-image-13324 alignright\" src=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/February-2025-THOTM-300x157.jpg\" alt=\"February 2025 - THOTM - Blog Cover Photo\" width=\"300\" height=\"157\" srcset=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/February-2025-THOTM-300x157.jpg 300w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/February-2025-THOTM-1024x535.jpg 1024w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/February-2025-THOTM-768x401.jpg 768w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/February-2025-THOTM-1080x564.jpg 1080w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/February-2025-THOTM-980x512.jpg 980w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/February-2025-THOTM-480x251.jpg 480w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/February-2025-THOTM.jpg 1200w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/>In February 2025, GoSecure Threat Hunters identified <\/span><b><span data-contrast=\"auto\">Rhysida<\/span><\/b><span data-contrast=\"auto\">, a ransomware group actively exploiting<\/span><span data-contrast=\"auto\"> stolen VPN credentials and search engine poisoning to infiltrate corporate networks. Rhysida\u2019s double-extortion tactic<\/span><b><span data-contrast=\"auto\">s<\/span><\/b><span data-contrast=\"auto\"> involve encrypting files while threatening to leak stolen sensitive data. The group has been observed delivering malware disguised as legitimate software, such as Microsoft Teams or Google Chrome, via poisoned search results. Once installed, the malware establishes <\/span><span data-contrast=\"auto\">persistence <\/span><span data-contrast=\"auto\">through scheduled tasks and executes via <\/span><b><span data-contrast=\"auto\">rundll32.exe<\/span><\/b><span data-contrast=\"auto\">, providing long-term access to compromised systems.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p aria-level=\"3\"><b><span data-contrast=\"auto\">Why This Matters<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:281,&quot;335559739&quot;:281}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Unlike conventional ransomware that solely encrypts dat<\/span><span data-contrast=\"auto\">a, Rhysida also exfiltrates personally identifiable information (PII), including passports and driver\u2019s licenses, increasing the risk of identity theft and regulatory fines. Their search engine poisoning tactic makes it easier for unsuspecting users to install malware without realizing it. This method bypasses traditional email phishing defenses, reinforcing the need for enhanced endpoint security and u<\/span><span data-contrast=\"auto\">ser awareness.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p aria-level=\"3\"><b><span data-contrast=\"auto\">Detection and Monitoring<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:281,&quot;335559739&quot;:281}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">GoSecure\u2019s Threat Hunters hypothesized that drive-by downloads were being leveraged for persistence in corporate environments. A high-severity detection rule was implemented to monitor for suspicious software installations executing schtasks.exe and rundll32.exe:<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"5\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Detection Rule: Schtasks Creating Task to Execute RunDLL32<\/span><\/b><br \/>\n<b><span data-contrast=\"auto\">Description:<\/span><\/b><span data-contrast=\"auto\"> Detects when <\/span><b><span data-contrast=\"auto\">schtasks.exe<\/span><\/b><span data-contrast=\"auto\"> is executed with \u201c\/create\u201d and \u201crundll32\u201d in the command line, a common persistence mechanism for malware.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"5\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Detection Rule: PowerShell with RunDLL32 in Command Line<\/span><\/b><br \/>\n<b><span data-contrast=\"auto\">Description:<\/span><\/b><span data-contrast=\"auto\"> Flags instances where <\/span><b><span data-contrast=\"auto\">powershell.exe<\/span><\/b><span data-contrast=\"auto\"> launches rundll32.exe, which may indicate unauthorized execution of malware.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/li>\n<\/ul>\n<p aria-level=\"3\"><b><span data-contrast=\"auto\">Recommendations<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:281,&quot;335559739&quot;:281}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">To mitigate the risks posed by Rhysida, GoSecure recommends the following measures:<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"7\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Train employees<\/span><\/b><span data-contrast=\"auto\"> to recognize misleading search results and avoid downloading software from unverified sources.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"7\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Enforce multi-factor authentication (MFA)<\/span><\/b><span data-contrast=\"auto\"> on externally facing services such as VPN access points.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"7\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Monitor scheduled tasks and system binaries<\/span><\/b><span data-contrast=\"auto\"> for unauthorized modifications.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"7\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Review endpoint logs<\/span><\/b><span data-contrast=\"auto\"> for suspicious rundll32.exe executions originating from newly installed software.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/li>\n<\/ul>\n<p aria-level=\"3\"><b><span data-contrast=\"auto\">Conclusion<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:281,&quot;335559739&quot;:281}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">This month\u2019s Threat Hunt highlights the growing use of search engine poisoning as an attack vector and the importance of proactive threat hunting to uncover ransomware activity before encryption occurs. GoSecure Titan\u00ae MXDR continuously monitors, detects, and mitigates emerging ransomware threats, ensuring organizations remain protected.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">For further details on strengthening your defenses or to discuss our findings, please contact us at <\/span><b><span data-contrast=\"auto\">(888)-287-5858<\/span><\/b><span data-contrast=\"auto\"> or <\/span><a href=\"mailto:info@gosecure.ai\"><b><span data-contrast=\"none\">info@gosecure.ai<\/span><\/b><\/a><span data-contrast=\"auto\">.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Stay secure!<\/span><\/b><br \/>\n<b><span data-contrast=\"auto\">Your GoSecure Threat Hunting Team<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p><span data-contrast=\"auto\"><img class=\"size-medium wp-image-13324 alignright\" src=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/February-2025-THOTM-300x157.jpg\" alt=\"February 2025 - THOTM - Blog Cover Photo\" width=\"300\" height=\"157\" \/>In February 2025, GoSecure Threat Hunters identified <\/span><b><span data-contrast=\"auto\">Rhysida<\/span><\/b><span data-contrast=\"auto\">, a ransomware group actively exploiting<\/span><span data-contrast=\"auto\"> stolen VPN credentials and search engine poisoning to infiltrate corporate networks. Rhysida\u2019s double-extortion tactic<\/span><b><span data-contrast=\"auto\">s<\/span><\/b><span data-contrast=\"auto\"> involve encrypting files while threatening to leak stolen sensitive data. The group has been observed delivering malware disguised as legitimate software, such as Microsoft Teams or Google Chrome, via poisoned search results. Once installed, the malware establishes <\/span><span data-contrast=\"auto\">persistence <\/span><span data-contrast=\"auto\">through scheduled tasks and executes via <\/span><b><span data-contrast=\"auto\">rundll32.exe<\/span><\/b><span data-contrast=\"auto\">, providing long-term access to compromised systems.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[437,556,654,563,632],"tags":[608,724,725,521,726,727,728,729,567,730],"class_list":["post-13331","post","type-post","status-publish","format-standard","hentry","category-avis-de-securite","category-cybersecurity-fr","category-incident-response-fr","category-ransomware-fr","category-threat-intelligence-fr","tag-cyber-threats-fr","tag-cybersecurity-awareness-fr","tag-double-extortion-fr","tag-endpoint-security-fr","tag-malware-detection-fr","tag-ransomware-group-fr","tag-rhysida-ransomware-fr","tag-search-engine-poisoning-fr","tag-threat-hunting-fr","tag-vpn-exploits-fr"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v23.0 (Yoast SEO v23.0) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Threat Hunt of the Month: Rhysida Ransomware Group Targeting VPNs and Search Engine Poisoning - GoSecure<\/title>\n<meta name=\"description\" content=\"Rhysida ransomware exploits stolen VPN credentials &amp; search engine poisoning to infiltrate networks. Learn how to detect &amp; mitigate it.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Threat Hunt of the Month: Rhysida Ransomware Group Targeting VPNs and Search Engine Poisoning\" \/>\n<meta property=\"og:description\" content=\"Rhysida ransomware exploits stolen VPN credentials &amp; search engine poisoning to infiltrate networks. Learn how to detect &amp; mitigate it.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/\" \/>\n<meta property=\"og:site_name\" content=\"GoSecure\" \/>\n<meta property=\"article:published_time\" content=\"2025-02-28T17:00:22+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-03-21T17:29:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/February-2025-THOTM-300x157.jpg\" \/>\n<meta name=\"author\" content=\"GoSecure\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@GoSecure_Inc\" \/>\n<meta name=\"twitter:site\" content=\"@GoSecure_Inc\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"GoSecure\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/\",\"url\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/\",\"name\":\"Threat Hunt of the Month: Rhysida Ransomware Group Targeting VPNs and Search Engine Poisoning - GoSecure\",\"isPartOf\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/February-2025-THOTM-300x157.jpg\",\"datePublished\":\"2025-02-28T17:00:22+00:00\",\"dateModified\":\"2025-03-21T17:29:08+00:00\",\"author\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/#\/schema\/person\/11f4bfed2ab7b748dfc255aa91baedca\"},\"description\":\"Rhysida ransomware exploits stolen VPN credentials & search engine poisoning to infiltrate networks. Learn how to detect & mitigate it.\",\"breadcrumb\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/#primaryimage\",\"url\":\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/February-2025-THOTM-300x157.jpg\",\"contentUrl\":\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/February-2025-THOTM-300x157.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/legacy.gosecure.ai\/fr\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Threat Hunt of the Month: Rhysida Ransomware Group Targeting VPNs and Search Engine Poisoning\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/#website\",\"url\":\"https:\/\/legacy.gosecure.ai\/fr\/\",\"name\":\"GoSecure\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/legacy.gosecure.ai\/fr\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/#\/schema\/person\/11f4bfed2ab7b748dfc255aa91baedca\",\"name\":\"GoSecure\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Threat Hunt of the Month: Rhysida Ransomware Group Targeting VPNs and Search Engine Poisoning - GoSecure","description":"Rhysida ransomware exploits stolen VPN credentials & search engine poisoning to infiltrate networks. Learn how to detect & mitigate it.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/","og_locale":"fr_FR","og_type":"article","og_title":"Threat Hunt of the Month: Rhysida Ransomware Group Targeting VPNs and Search Engine Poisoning","og_description":"Rhysida ransomware exploits stolen VPN credentials & search engine poisoning to infiltrate networks. Learn how to detect & mitigate it.","og_url":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/","og_site_name":"GoSecure","article_published_time":"2025-02-28T17:00:22+00:00","article_modified_time":"2025-03-21T17:29:08+00:00","og_image":[{"url":"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/February-2025-THOTM-300x157.jpg"}],"author":"GoSecure","twitter_card":"summary_large_image","twitter_creator":"@GoSecure_Inc","twitter_site":"@GoSecure_Inc","twitter_misc":{"\u00c9crit par":"GoSecure","Dur\u00e9e de lecture estim\u00e9e":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/","url":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/","name":"Threat Hunt of the Month: Rhysida Ransomware Group Targeting VPNs and Search Engine Poisoning - GoSecure","isPartOf":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/#primaryimage"},"image":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/#primaryimage"},"thumbnailUrl":"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/February-2025-THOTM-300x157.jpg","datePublished":"2025-02-28T17:00:22+00:00","dateModified":"2025-03-21T17:29:08+00:00","author":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/#\/schema\/person\/11f4bfed2ab7b748dfc255aa91baedca"},"description":"Rhysida ransomware exploits stolen VPN credentials & search engine poisoning to infiltrate networks. Learn how to detect & mitigate it.","breadcrumb":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/#primaryimage","url":"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/February-2025-THOTM-300x157.jpg","contentUrl":"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/February-2025-THOTM-300x157.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2025\/02\/28\/threat-hunt-of-the-month-rhysida-ransomware-group-targeting-vpns-and-search-engine-poisoning\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/legacy.gosecure.ai\/fr\/"},{"@type":"ListItem","position":2,"name":"Threat Hunt of the Month: Rhysida Ransomware Group Targeting VPNs and Search Engine Poisoning"}]},{"@type":"WebSite","@id":"https:\/\/legacy.gosecure.ai\/fr\/#website","url":"https:\/\/legacy.gosecure.ai\/fr\/","name":"GoSecure","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/legacy.gosecure.ai\/fr\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"fr-FR"},{"@type":"Person","@id":"https:\/\/legacy.gosecure.ai\/fr\/#\/schema\/person\/11f4bfed2ab7b748dfc255aa91baedca","name":"GoSecure"}]}},"_links":{"self":[{"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/posts\/13331","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/comments?post=13331"}],"version-history":[{"count":0,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/posts\/13331\/revisions"}],"wp:attachment":[{"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/media?parent=13331"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/categories?post=13331"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/tags?post=13331"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}