#StopRansomware: Ghost (Cring) Ransomware
ID: 07926bb8-b00f-588d-9ccd-61e480c6bdfe
STIX ID: report--07926bb8-b00f-588d-9ccd-61e480c6bdfe
Feed Name: CISA Cybersecurity Advisories
**Executive summary:** This joint FBI/CISA/MS-ISAC advisory outlines Ghost (Cring) ransomware activity—an opportunistic, China-located criminal group that exploits unpatched public-facing services and uses Cobalt Strike, web shells, and various open-source tools to deploy ransomware (Cring.exe, Ghost.exe, ElysiumO.exe, Locker.exe). The advisory provides technical details, MITRE ATT&CK mappings, IoCs (file hashes, tools, ransom emails, TOX IDs), observed impacts (file encryption, shadow copy deletion), and prioritized mitigations and reporting guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
