Introduction
aka Cring / Ghost (Cring)
Beginning early 2021, Ghost actors began attacking victims whose internet facing services ran outdated versions of software and firmware. This indiscriminate targeting of networks containing vulnerabilities has led to the compromise of organizations across more than 70 countries, including organizations in China. Ghost actors, located in China, conduct these widespread attacks for financial gain. Affected victims include critical infrastructure, schools and universities, healthcare, government networks, religious institutions, technology and manufacturing companies, and numerous small- and medium-sized businesses.
Ghost actors rotate their ransomware executable payloads, switch file extensions for encrypted files, modify ransom note text, and use numerous ransom email addresses, which has led to variable attribution of this group over time. Names associated with this group include Ghost, Cring, Crypt3r, Phantom, Strike, Hello, Wickrme, HsHarada, and Rapture. Samples of ransomware files Ghost used during attacks are: Cring.exe, Ghost.exe, ElysiumO.exe, and Locker.exe.
https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-050a
Activities and Tactics
Information pending cataloguing.
Notable Campaigns
Information pending cataloguing.
Tactics, Techniques, and Procedures (TTPs)
Information pending cataloguing.
Notable Indicators of Compromise (IOCs)
No atomic indicators are listed in this profile. The APTnotes snapshot indexes 1 public reports that may contain IOCs; see Source Attribution for dataset links.
Malware and Tools
- China Chopper:
- CyberGate:
- Small-Net:
- Cyber Eye RAT:
- Ghost:
- CrossRat:
Attribution and Evidence
Information pending cataloguing.
References
References pending cataloguing.
Recent News
Latest articles from security news feeds mentioning this actor.
- Ghost hackers: the cybersecurity mystery that nobody has solved TechCrunch - 2026-05-26T
- Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks The Hacker News - 2026-05-25T
- Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign BleepingComputer - 2026-05-24T