logo

FBI and CISA Warn Against Ghost Ransomware in Latest Advisory

ID: 40097c0f-0e60-540b-a9c3-f16a751777c3

STIX ID: report--40097c0f-0e60-540b-a9c3-f16a751777c3

Feed Name: Halcyon Blog

Threat Score
78/100

Date Published: 2025-03-18

Date Updated: 2026-04-28

...
...

On February 19, 2025, the FBI and CISA released a joint advisory warning of active, global operations by the Ghost ransomware group—active since 2021 and responsible for recent attacks—detailing their use of known CVE exploits (e.g., FortiOS CVE-2018-13379, Adobe ColdFusion flaws), tools like Cobalt Strike, web shells, credential theft, lateral movement, data exfiltration, and deployment of ransomware (Cring.exe, Ghost.exe), along with provided IOCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.