Recent Ghost/Cring ransomware activity prompts alert from FBI, CISA
ID: 31a1f87e-5078-5dce-b75e-76ce5185af6a
STIX ID: report--31a1f87e-5078-5dce-b75e-76ce5185af6a
Feed Name: The Record from Recorded Future News
The FBI and CISA alert warns that the Ghost/Cring ransomware group has been actively exploiting long-unpatched internet-facing vulnerabilities—including in Fortinet appliances, Adobe ColdFusion, and Exchange (ProxyShell)—to rapidly compromise organizations across more than 70 countries and sectors such as critical infrastructure, healthcare, education, government, and manufacturing; actors deploy common tools (Cobalt Strike, Mimikatz), use filenames like Cring.exe/Ghost.exe, demand large ransoms, and typically move quickly from initial access to encryption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
