Site navigation

FBI Issues Stark Warning About Ghost Ransomware Group

Elizabeth Greenberg

,

ghost ransomware
Authorities are urging for better cybersecurity posture as a ransomware group targets unsuspecting small businesses.

Authorities in the US have issued novel details about the Chinese-based Ghost ransomware group, saying that it has targeted organisations in over 70 countries.

The ransomware group is also known as Cring, Phantom, Crypt3r, Strike, Wickrme, Hello, Rapture, and HsHarada, and is typically financially motivated.

The Cybersecurity Infrastructure and Security Agency (CISA), FBI, and the Multi-State Information Sharing and Analysis Centre (MS-ISAC) issued to the new advisory, which detailed new tactics employed by the ransomware group.

Ghost typically exploits known vulnerabilities across public-facing systems, often employing Cobalt Strike for privilege escalation and credential access, lateral movement, and domain account discovery.

“Ghost actors have been observed uploading a web shell to a compromised server and leveraging Windows Command Prompt and/or PowerShell to download and execute Cobalt Strike Beacon malware that is then implanted on victim systems,” the US authorities reported.

“Persistence is not a major focus for Ghost actors, as they typically only spend a few days on victim networks. In multiple instances, they have been observed proceeding from initial compromise to the deployment of ransomware within the same day.”

While the ransomware typically threatens to sell data if a ransom is not paid, the report noted that Ghost typically do not extract a significant amount of data that would cause significant harm to victims if a leak were to progress.


Recommended reading


Ghost typically goes after easy targets, and will even abandon attacks when met with security barriers and obstacles to lateral movement, the report said.

This coincides with most of the group’s targets being small and medium sized businesses, giving emphasis to the need of solid cyber hygiene and a sturdy security posture, even for smaller companies.

CISA therefore issued guidance along with the advisory, urging companies to regularly back up their systems and store backups separately from their typical sources, patch known vulnerabilities as soon as possible, and segment networks to prevent lateral movement of cyber-criminals.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data