logo

Ghost Ransomware: Striking Before You Even Know It’s There by Lucie Cardiet

ID: eeb8e5c1-a109-53fb-807f-ab23d5af3d94

STIX ID: report--eeb8e5c1-a109-53fb-807f-ab23d5af3d94

Feed Name: Vectra AI Blog

Threat Score
75/100

Date Published: 2025-02-26

Date Updated: 2026-05-01

...
...

Ghost (aka Cring, Crypt3r, Phantom, Strike, Hello, Wickrme, HsHarada, Rapture) is a fast-moving ransomware operator that exploits unpatched public-facing software (e.g., Fortinet, Exchange, ColdFusion) to gain immediate access, escalate privileges (SharpZeroLogon, BadPotato), disable endpoint defenses, move laterally via PowerShell/WMI/SMB/RDP, and encrypt files—often within hours or the same day—demanding cryptocurrency ransoms rather than prioritizing long-term persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.