FBI and CISA Warn Against Ghost Ransomware in Latest Advisory
ID: 40097c0f-0e60-540b-a9c3-f16a751777c3
STIX ID: report--40097c0f-0e60-540b-a9c3-f16a751777c3
Feed Name: Halcyon Blog
Threat Score
On February 19, 2025, the FBI and CISA released a joint advisory warning of active, global operations by the Ghost ransomware group—active since 2021 and responsible for recent attacks—detailing their use of known CVE exploits (e.g., FortiOS CVE-2018-13379, Adobe ColdFusion flaws), tools like Cobalt Strike, web shells, credential theft, lateral movement, data exfiltration, and deployment of ransomware (Cring.exe, Ghost.exe), along with provided IOCs and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
