The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) are releasing this joint advisory to disseminate known Ghost (Cring)— (“Ghost”)—ransomware IOCs and TTPs identified through FBI investigation as recently as January 2025. Beginning early 2021, Ghost actors began attacking victims whose internet facing services ran outdated versions of software and firmware.
This indiscriminate targeting of networks containing vulnerabilities has led to the compromise of organizations across more than 70 countries, including organizations in China. Ghost actors, located in China, conduct these widespread attacks for financial gain. Affected victims include critical infrastructure, schools and universities, healthcare, government networks, religious institutions, technology and manufacturing companies, and numerous small- and medium-sized businesses.
Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division
Related:
- Medical data breach could impact thousands from New Hampshire
January 15, 2024
A Massachusetts-based medical company is contacting over 900,000 people whose personal information may have been compromised in a data breach. In a letter to the New Hampshire attorney general’s office, Transformative Healthcare said the breach happened last year when someone gained access to an archived copy of data that previously belonged to Fallon Ambulance Service. Read more… Source: MSN ...
- Dallas says cyberattack targeted more people than previously disclosed
January 11, 2024
Hackers who targeted the city of Dallas had access to the addresses, Social Security numbers and other personal information of nearly 300 more people than what had been previously disclosed to the public, city officials now say. The city’s spokesperson confirmed on Wednesday that further internal investigations into the cyberattack determined an additional 293 people, including ...
- Texas-based care provider HMG Healthcare says hackers stole unencrypted patient data
January 10, 2024
Texas-based care provider HMG Healthcare has confirmed that hackers accessed the personal data of residents and employees, but says it has been unable to determine what types of data were stolen. HMG Healthcare is headquartered in The Woodlands, Texas, and provides a range of services, including memory care, rehabilitation, and assisted living. HMG’s website says it ...
- SEC says ‘compromised’ account to blame for tweet approving Bitcoin ETF
January 10, 2024
The Securities and Exchange Commission (SEC) said Tuesday that a post sent from the agency’s account on the social platform X/Twitter announcing the approval of a long-awaited bitcoin exchange-traded fund was “unauthorized”, and that the agency’s account had been “compromised”. The price of bitcoin briefly spiked more than $1,000 after the post on X claimed: “The ...
- AI aids nation-state hackers but also helps US spies to find them, says NSA cyber director
January 9, 2024
Nation state-backed hackers and criminals are using generative AI in their cyberattacks, but U.S. intelligence is also using artificial intelligence technologies to find malicious activity, according to a senior U.S. National Security Agency official. “We already see criminal and nation state elements utilizing AI. They’re all subscribed to the big name companies that you would expect ...
- Fidelity National Financial says hackers stole data on 1.3 million customers
January 9, 2024
Real estate services giant Fidelity National Financial (FNF) has confirmed hackers stole data on 1.3 million of its customers during a November cyberattack that knocked the company offline for a week. FNF said in a filing Tuesday with federal regulators: “We determined that an unauthorized third-party accessed certain FNF systems, deployed a type of malware that ...

