CISA, FBI Warn of China-Based Ghost Ransomware Threatening Global Critical Infrastructure
February 21, 2025
Active since early 2021, Ghost ransomware primarily targets outdated publicly facing services and exploits known vulnerabilities in internet-facing servers.
Key tactics, techniques, and procedures (TTPs) identified include the use of PowerShell for executing commands, disabling Microsoft Defender to evade detection, and creating local accounts for persistence in compromised systems.
In response to the evolving threat, AttackIQ released an attack graph showcasing the TTPs of Ghost ransomware, aimed at helping organizations assess their security controls.
Recommendations for detection include monitoring command line activities related to the deletion of volume shadow copies and the use of PowerShell to download malicious payloads.
Operated by a group based in China, Ghost ransomware has compromised organizations in over 70 countries, affecting critical infrastructure, healthcare, and educational institutions.
On February 19, 2025, CISA, the FBI, and MS-ISAC issued a Cybersecurity Advisory regarding Ghost ransomware, also known as Cring, outlining its tactics and indicators of compromise identified through FBI investigations.
The ransomware employs advanced encryption methods using AES-256 and RSA-4096 algorithms, while also inhibiting system recovery by deleting volume shadow copies.
Ghost operators utilize strategies such as rotating ransomware payloads and modifying ransom notes to evade detection and attribution.
CISA advises organizations to review their patching and detection recommendations to defend against attacks and prioritize the detection of techniques used by Ghost ransomware.
AttackIQ emphasizes the importance of continuous testing and validation of security controls to enhance defenses against Ghost ransomware and similar threats.
Summary based on 1 source
Get a daily email with more Tech stories
Source
![[CISA AA25-050A] #StopRansomware: Ghost (Cring) Ransomware](https://cdn.brief.news/cdn-cgi/image/fit=contain,width=160/images/links/71c1f7ffa253f5e5d51fbfbcb123e99a51c0b48329221767e5826b6d0f592d11e914f788587977d1045364e84a3dbdc834bfc52031717f7d0368a8f5344bf200.png)
Security Boulevard • Feb 20, 2025
[CISA AA25-050A] #StopRansomware: Ghost (Cring) Ransomware