Authorities in the US have issued novel details about the Chinese-based Ghost ransomware group, saying that it has targeted organisations in over 70 countries.
The ransomware group is also known as Cring, Phantom, Crypt3r, Strike, Wickrme, Hello, Rapture, and HsHarada, and is typically financially motivated.
The Cybersecurity Infrastructure and Security Agency (CISA), FBI, and the Multi-State Information Sharing and Analysis Centre (MS-ISAC) issued to the new advisory, which detailed new tactics employed by the ransomware group.
Ghost typically exploits known vulnerabilities across public-facing systems, often employing Cobalt Strike for privilege escalation and credential access, lateral movement, and domain account discovery.
“Ghost actors have been observed uploading a web shell to a compromised server and leveraging Windows Command Prompt and/or PowerShell to download and execute Cobalt Strike Beacon malware that is then implanted on victim systems,” the US authorities reported.
“Persistence is not a major focus for Ghost actors, as they typically only spend a few days on victim networks. In multiple instances, they have been observed proceeding from initial compromise to the deployment of ransomware within the same day.”
While the ransomware typically threatens to sell data if a ransom is not paid, the report noted that Ghost typically do not extract a significant amount of data that would cause significant harm to victims if a leak were to progress.
Recommended reading
- ‘Big Game’ Ransomware Tactics Drives Spike in Attacks
- As-a-Service Platforms Drive Four-fold Ransomware Increase
- UK Proposes Ban on Public Sector Ransomware Payments
- Ransomware Payouts Plummet by £350M in 2024
Ghost typically goes after easy targets, and will even abandon attacks when met with security barriers and obstacles to lateral movement, the report said.
This coincides with most of the group’s targets being small and medium sized businesses, giving emphasis to the need of solid cyber hygiene and a sturdy security posture, even for smaller companies.
CISA therefore issued guidance along with the advisory, urging companies to regularly back up their systems and store backups separately from their typical sources, patch known vulnerabilities as soon as possible, and segment networks to prevent lateral movement of cyber-criminals.





