#StopRansomware: Ghost (Cring) Ransomware


The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) are releasing this joint advisory to disseminate known Ghost (Cring)— (“Ghost”)—ransomware IOCs and TTPs identified through FBI investigation as recently as January 2025. Beginning early 2021, Ghost actors began attacking victims whose internet facing services ran outdated versions of software and firmware.

This indiscriminate targeting of networks containing vulnerabilities has led to the compromise of organizations across more than 70 countries, including organizations in China. Ghost actors, located in China, conduct these widespread attacks for financial gain. Affected victims include critical infrastructure, schools and universities, healthcare, government networks, religious institutions, technology and manufacturing companies, and numerous small- and medium-sized businesses.

Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division


Sign up for our Newsletter


Related:

  • FBI Warns of Scammers Impersonating the IC3

    July 20, 2026

    This Public Service Announcement contains updated information about an ongoing fraud scheme where criminal scammers are impersonating FBI personnel facilitating Internet Crime Complaint Center (IC3) complaints to deceive and revictimize individuals. This scheme combines several exploitation tactics to include the targeting of previous victims, the use of artificial intelligence (AI)-generated videos to create fictitious or misleading promotional ...

  • Hackers breached DHS after alarms were twice ruled ‘false positives’

    July 17, 2026

    Hackers managed to find their way into the US Department of Homeland Security’s primary information sharing platform, gaining unfettered access to the HSIN network that hosts unclassified information that multiple US agencies and international rely on. The hack allowed the attackers to modify server files, run malicious code and steal credential files while installing backdoors and ...

  • Coca-Cola suspended production at its Fairlife dairy after a ransomware attack

    July 16, 2026

    U.S. beverage maker Coca-Cola said one of its dairy subsidiaries was hacked and that it’s shutting down its operations for the foreseeable future. The multinational giant said in a disclosure with the U.S. Securities and Exchange Commission that its Fairlife dairy company was hit by ransomware and that its production systems are affected. The company said that ...

  • Trump administration subpoenas New York Times journalists over new Air Force One reporting

    July 11, 2026

    The Trump administration has issued subpoenas to several New York Times journalists after the newspaper reported on security concerns with the president’s new plane. The Times said its journalists were subpoenaed on Friday by the US justice department to testify before a federal grand jury in Manhattan five days later, marking the latest effort by the Trump White ...

  • Florida ransomware negotiator convicted for helping ransomware gang extort US companies

    July 10, 2026

    Florida man Angelo Martino has been sentenced to more than five years in prison for conspiring with hackers to deploy ransomware during his job as a ransomware negotiator for a U.S. cybersecurity company. The U.S. Department of Justice confirmed the sentence on Thursday, noting that the government seized more than $10 million worth of cryptocurrency and assets. Martino ...

  • An unnamed US county paid $1M extortion demand to cybercriminals

    July 9, 2026

    A US county reportedly paid $1 million to Kairos, an extortion gang that claimed to have stolen more than 2 TB of data, but the county never received independently verifiable proof that the stolen files had been deleted – just the criminals’ promise. This means the county’s stolen files may turn up for sale on a ...