UPDATED 19:26 EDT / FEBRUARY 20 2025

SECURITY

CISA and FBI warns Ghost ransomware is targeting critical infrastructure and businesses

The U.S. Cybersecurity and Infrastructure Agency, along with the Federal Bureau of Investigation and the Multi-State Information Sharing and Analysis Center, has issued a joint advisory warning of the activities of Ghost ransomware, also known as Cling.

The group behind Ghost ransomware allegedly operates out of China and has targeted organizations in more than 70 countries, including critical infrastructure, schools, healthcare, government networks and businesses, for financial gain.

Ghost ransomware operates by exploiting unpatched vulnerabilities in widely used software to gain unauthorized access to targeted systems. Upon gaining access to targeted systems, the attackers deploy web shells and use command-line tools to establish persistence, escalate privileges and move laterally within the network.

Those behind the ransomware commonly leverage vulnerabilities in Fortinet, Adobe ColdFusion, Microsoft SharePoint and Microsoft Exchange, known as ProxyShell, to breach systems.

Ghost ransomware is known for its rapid execution, encrypting files within hours of initial access. After gaining control, the attackers deploy Cobalt Strike Beacon malware and use open-source tools to disable security defenses and prepare for the final ransomware payload, allowing them to lock down critical files and render them inaccessible to victims.

Typical of modern-day ransomware operations, Ghost ransomware doesn’t only encrypt files but also exfiltrates data before launching the attack to set up a double-tap situation: Victims are told that if they don’t pay the ransom demands, their data will be released along with remaining encrypted. Notably, though, the advisory states that the actual amount of data exfiltrated is relatively small, suggesting that data theft may serve more as a psychological pressure tactic than a core operational strategy.

The ransom demands from the Ghost group can range from tens of thousands to hundreds of thousands of dollars, typically payable in cryptocurrency. Victims receive a ransom note instructing them on how to contact the attackers and make payment in exchange for a decryption tool.

The advisory from CISA, FBI and MS-ISAC, issued Wednesday, stresses the need to take proactive defense measures against Ghost ransomware and other types of ransomware. Organizations are urged to promptly apply security patches, particularly for known vulnerabilities the group exploits. Additionally, network segmentation and restricting access to critical systems can help prevent lateral movement in the event of an initial breach.

Darren Guccione, co-founder and chief executive of cybersecurity software startup Keeper Security Inc., told SiliconANGLE via email that “the Ghost ransomware campaign highlights the persistent reality that adversaries exploit known vulnerabilities faster than many organizations can patch them” and that the advisory “reinforces the critical need for proactive risk management – security leaders must ensure that software, firmware and identity systems are continuously updated and hardened against exploitation.”

Image: SiliconANGLE/Grok 3

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.