Ghost Ransomware Targets Orgs in 70+ Countries
ID: 255b4137-b5ec-56e7-8b55-d6a5855169e4
STIX ID: report--255b4137-b5ec-56e7-8b55-d6a5855169e4
Feed Name: Dark Reading
Date Published: 2025-02-20
Date Updated: 2026-05-05
Author: Elizabeth Montalbano, Contributing Writer
The CISA advisory describes Ghost, a prolific China-backed ransomware group active since 2021 that has impacted victims in over 70 countries by exploiting unpatched Internet-facing systems (e.g., Fortinet FortiOS, Adobe ColdFusion, Microsoft SharePoint and Exchange ProxyShell). Ghost actors move rapidly from initial access to encryption—often within a single day—use Cobalt Strike for command-and-control, rotate ransomware binaries and ransom notes, claim data exfiltration to coerce payment, and typically demand tens to hundreds of thousands of dollars; the advisory provides IoCs and emphasizes patching and Cobalt Strike detection as primary mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
