logo

Recent Ghost/Cring ransomware activity prompts alert from FBI, CISA

ID: 31a1f87e-5078-5dce-b75e-76ce5185af6a

STIX ID: report--31a1f87e-5078-5dce-b75e-76ce5185af6a

Feed Name: The Record from Recorded Future News

Threat Score
78/100

Date Published: 2025-02-19

Date Updated: 2026-05-01

...
...

The FBI and CISA alert warns that the Ghost/Cring ransomware group has been actively exploiting long-unpatched internet-facing vulnerabilities—including in Fortinet appliances, Adobe ColdFusion, and Exchange (ProxyShell)—to rapidly compromise organizations across more than 70 countries and sectors such as critical infrastructure, healthcare, education, government, and manufacturing; actors deploy common tools (Cobalt Strike, Mimikatz), use filenames like Cring.exe/Ghost.exe, demand large ransoms, and typically move quickly from initial access to encryption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.