#StopRansomware: Ghost (Cring) Ransomware


The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) are releasing this joint advisory to disseminate known Ghost (Cring)— (“Ghost”)—ransomware IOCs and TTPs identified through FBI investigation as recently as January 2025. Beginning early 2021, Ghost actors began attacking victims whose internet facing services ran outdated versions of software and firmware.

This indiscriminate targeting of networks containing vulnerabilities has led to the compromise of organizations across more than 70 countries, including organizations in China. Ghost actors, located in China, conduct these widespread attacks for financial gain. Affected victims include critical infrastructure, schools and universities, healthcare, government networks, religious institutions, technology and manufacturing companies, and numerous small- and medium-sized businesses.

Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division


Sign up for our Newsletter


Related:

  • Facebook, X rush to delete Trump attacker Ryan Wesley Routh from social media

    September 15, 2024

    Social media companies including Meta’s Facebook and Elon Musk-owned X (formerly Twitter) are rushing to delete the pages associated with Ryan Wesley Routh from their platforms. While X has removed Routh’s profile from its platform, Facebook has removed all the posts he shared on his profile. Meta has not deleted Routh’s profile from Facebook yet. LinkedIn ...

  • Chinese-made cargo equipment enables cyber, espionage risks in US ports

    September 12, 2024

    A year-long probe led by GOP members of two House panels found that numerous seaports around the U.S. contain technology originating from Chinese manufacturers that could enable espionage and sabotage. The study conducted by lawmakers and staff on the House Homeland Security Committee and Select Committee on the Chinese Communist Party said that it was an ...

  • Thousands of US medical professionals have data exposed in major data breach

    September 11, 2024

    Researchers have found a database backup belonging to Florida-based recruitment company MNA Healthcare left unsecured online, leaving the details of thousands of workers open to anyone. The company offers staffing services for healthcare workers and matches them with hospitals and organizations across nine states. The leaked information included full names, addresses, phone numbers, job titles, work ...

  • Nearly 1M Medicare beneficiaries potentially affected after data breach

    September 10, 2024

    Nearly 1 million Medicare beneficiaries are being warned that their personal information may have been compromised in a cybersecurity incident last year. The Centers for Medicare & Medicaid Services (CMS) and Wisconsin Physicians Service Insurance Corporation (WPS), the contractor that utilized the affected MOVEit software, said last week that 946,801 people on Medicare were notified that ...

  • Japan: JMSDF set to establish a new “Fleet Information Warfare” command

    September 9, 2024

    The move would strengthen the JMSDF’s response capabilities to integrated information warfare, especially in the cognitive dimension. Most notably, the new reorganization process will abolish the current Fleet Intelligence Command (艦隊情報群), the only specialized intelligence unit in the JMSDF. The move came as part of a major organizational restructuring of the JMSDF. As Naval News reported ...

  • US sanctions fail to deter Predator spyware utilization

    September 6, 2024

    Intellexa Group’s Predator spyware has experienced a resurgence in activity following a decline spurred by sanctions imposed by the Biden administration, reports The Record, a news site by cybersecurity firm Recorded Future. Angola and the Democratic Republic of Congo, which is a new Intellexa client, may have leveraged new Predator infrastructure to enable spyware staging and ...