The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) are releasing this joint advisory to disseminate known Ghost (Cring)— (“Ghost”)—ransomware IOCs and TTPs identified through FBI investigation as recently as January 2025. Beginning early 2021, Ghost actors began attacking victims whose internet facing services ran outdated versions of software and firmware.
This indiscriminate targeting of networks containing vulnerabilities has led to the compromise of organizations across more than 70 countries, including organizations in China. Ghost actors, located in China, conduct these widespread attacks for financial gain. Affected victims include critical infrastructure, schools and universities, healthcare, government networks, religious institutions, technology and manufacturing companies, and numerous small- and medium-sized businesses.
Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division
Related:
- German Citizen Charged with Laundering Funds Linked to Prominent Darknet Marketplace “Dream Market”
May 13, 2026
Owe Martin Andresen, the suspected main administrator of Dream Market, one of the largest illicit darknet marketplaces before its 2019 shutdown, has been indicted for an alleged scheme to launder funds from Dream Market’s administrator accounts. Andresen was arrested last week in Germany on parallel charges brought by the German government. “Andresen allegedly channeled commissions earned ...
- Disgraced US gov software contractor found guilty of database destruction
May 8, 2026
A Virginia man, Sohaib Akhter, faces decades in prison after a jury convicted him of being involved in a scheme to delete approximately 96 databases containing US government data. The events of the case transpired around two weeks before the twin brothers allegedly involved were fired from their jobs at a software supplier to the US ...
- Poland says hackers breached water treatment plants, and the US is facing the same threat
May 8, 2026
Poland’s intelligence service said it detected attacks on five water treatment plants where hackers could have taken control of the industrial equipment inside, including, in the worst case, tampering with the safety of the water supply. The story is relevant beyond Poland’s borders: U.S. water infrastructure has faced similar threats in recent years. In 2021, a ...
- DOJ says ransomware gang tapped into Russian government databases
May 6, 2026
A U.S. court has sentenced Latvian hacker Deniss Zolotarjovs to more than eight years in prison following his conviction for carrying out ransomware attacks. The Justice Department accused the hacker of working for a notorious Russian ransomware gang called Karakurt, which was led by former leaders of the Akira and Conti ransomware gangs, who were sanctioned ...
- How ChatGPT conversations became ‘a treasure trove’ of evidence in criminal investigations
May 2, 2026
Days before two University of South Florida graduate students went missing last month, a roommate of one of the students allegedly asked the AI chatbot ChatGPT an unusual question. “What happens if a human has a put (sic) in a black garbage bag and thrown in a dumpster,” Hisham Abugharbieh asked on April 13, according to ...
- FBI: Hackers making millions from stolen cargo – losses ‘surged’ to nearly $725 million in 2025
May 1, 2026
The FBI has warned cybercriminals are increasingly targeting cargo shipments with hacking and impersonation tactics – and making a hefty profit doing so. With incidents rising 18% in 2025 and the average value per theft up around 36% (to $273,990) due to criminals targeting high-value goods, losses in the US and Canada alone hit around $725 ...

