EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Ransomware

#StopRansomware: Ghost (Cring) Ransomware

Official source
EudorIA operational summary

What it means

Priority 90/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Ghost (Cring). Le misure indicate vanno confrontate con esposizione, identita, segmentazione e capacita di ripristino.

Why it matters

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Potential operational benefits

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
AudienceITSOCCISOManagement
Information centre

Translation in progress

CISA

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Cybersecurity Advisory #StopRansomware: Ghost (Cring) Ransomware Release Date February 19, 2025 Alert Code AA25-050A Related topics: Cyber Threats and Response , Incident Response , Malware, Phishing, and Ransomware Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Ghost (Cring) Ransomware Activity Maintain regular system backups stored separately from the source systems which cannot be altered or encrypted by potentially compromised network devices [CPG 2.R]. Patch known vulnerabilities by applying timely security updates to operating systems, software, and firmware within a risk-informed timeframe [CPG 2.F]. Common Vulnerabilities and Exposures (CVE): CVE-2018-13379, CVE-2010-2861, CVE-2009-3960, CVE-2021-34473, CVE-2021-34523, CVE-2021-31207. Segment networks to restrict lateral movement from initial infected devices and other devices in the same organization [CPG 2.F]. Require Phishing-Resistant MFA for access to all privileged accounts and email services accounts. Summary Note: This joint Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit stopransomware.gov to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources. The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) are releasing this joint advisory to disseminate known Ghost (Cring)—(“G

Indicatori CISA verificabili

65 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Copertura parziale: sono mostrati solo gli indicatori verificati e interpretabili.

Ultima verifica: 2026-09-26T06:00:37.959413+00:00

Scarica STIX 2.1

Questo allegato contiene 1 indicatori incompleti o non interpretabili, conservati nell'originale ma esclusi dall'export operativo. I valori mancanti non sono stati dedotti.

TipoIndicatore (non cliccabile)File
MD5db38ef2e3d4d8cb785df48f458b35090sock.txt
MD5625bd7275e1892eac50a22f8b4a6355disx.txt
SHA-10979b2202e650444ffe61d9762cb756e7cdd6bf0isx.txt
SHA-256e0821121726dbe78c6423af0f46b2e938acf8ce74d4674751af4030d84be972aisx.txt
SSDEEP49152:Jri7bgnq+Tk/hkYD168uq6StA66ztND3Tv82putV6Cl:Jr0mFk/hX1/6h9rQ8isx.txt
MD5a2fd181f57548c215ac6891d000ec6b9main.txt
SHA-192e529aefd28e6a32b0ab9ef2289d211abbe435dmain.txt
SHA-2564a324fc6ab18f552b8669404219ba4f16ad167c6e534b61f5bc7831534eb23a1main.txt
SSDEEP49152:IPSQZsb3bimRrb/TwvO90d7HjmAFd4A64nsfJnP1Q3Wq9+YgSlD4byD1CFe9c74G:J3bim3OIFF7n2PMYmain.txt
MD5ff52fdf84448277b1bc121f592f753c5sp.txt
MD50a5c4ad3ec240fbfd00bdc1d36bd54ebx86.log
MD5c3b8f6d102393b4542e9f951c9435255x86.log
SHA-10183cf7515729edddc070ed0d564222b1d1e76d6x86.log
SHA-2564e9bb2de5712e0fdb7270cce45af0afb089c44d4424aa7cf8ca98219ec45a9c1x86.log
SSDEEP24576:oZSlJ2VULwYcNRv/D3cX8rJDAhPCDWBl4Z6ZH6GjMRCDPx9UhvkqVaTEKUYD1I/l:ITcXna6ZHru15YD1nzDsRkOXkyN47xCx86.log
MD5ef6a213f59f3fbee2894bd6734bbaed2Locker.exe
MD5d1c5e7b8e937625891707f8b4b594314ElysiumO.exe
SHA-1f031bba881a735e45b757548b9b981cc2dcd87ecElysiumO.exe
SHA-256c8acd8e65b46c86d0d01e961358bc6ab9aec70f90a57829aa15e39add536b5c8ElysiumO.exe
SSDEEP768:YBMQI6dpTIAcU+fipHZIpryQBwGZKBaja+jUZbB1hIl:YKAIAJJp5IIQCGVja+wZbB1elElysiumO.exe
MD5c9e35b5c1dc8856da25965b385a26ec4ElysiumO.exe
MD529e44e8994197bdb0c2be6fc5dfc15c2ElysiumO.exe
MD5d9c019182d88290e5489cdf3b607f982Ghost.exe
MD534b3009590ec2d361f07cac320671410Ghost.exe
email-addrrainbowforever[@]skiff[.]com
email-addrghost1998[@]tutamail[.]com
email-addrr[.]heisler[@]skiff[.]com
email-addrgenesis1337[@]tutanota[.]com
email-addrsummerkiller[@]mailfence[.]com
email-addrlockhelp1998[@]skiff[.]com
email-addrkev1npt[@]tuta[.]io
email-addrfileunlock[@]onionmail[.]org
email-addrshadowghost[@]skiff[.]com
email-addrkellyreiff[@]tutanota[.]com
email-addrevilcorp[@]skiff[.]com
email-addrghostsbackup[@]skiff[.]com
email-addrretryit1998[@]tutamail[.]com
email-addrghosts1337[@]tuta[.]io
email-addrcrptbackup[@]skiff[.]com
email-addrretryit1998[@]mailfence[.]com
email-addrghosts1337[@]skiff[.]com
email-addrcringghost[@]skiff[.]com
email-addrghostbackup[@]skiff[.]com
email-addrasauribe[@]tutanota[.]com
email-addrrainbowforever[@]tutanota[.]com
email-addrrsacrpthelp[@]skiff[.]com
email-addrhsharada[@]skiff[.]com
MD5ac58a214ce7deb3a578c10b97f93d9c3iex.txt; iex.exe; pro.txt
SHA-144396e35b328247dafd23b4a26b9d69c0011f54aiex.txt; iex.exe; pro.txt
SHA-2560500c9d0b91e62993447cdcf5f691092aff409eca24080ce149f34e48a0445e0iex.txt; iex.exe; pro.txt
SSDEEP49152:vSthBqV3933Mrb/TQvO90d7HjmAFd4A64nsfJkxw4d9WN0+YgSlD47zD1yRMV1r5:h3933vuIA1rYi0PMYiex.txt; iex.exe; pro.txt
email-addrshadowghosts[@]tutanota[.]com
email-addrjust4money[@]tutanota[.]com
email-addrsummerkiller[@]tutanota[.]com
email-addrd3svc[@]tuta[.]io
email-addrd3crypt[@]onionmail[.]org
email-addrsdghost[@]onionmail[.]org
email-addrfortihooks[@]protonmail[.]com
email-addrwebroothooks[@]tutanota[.]com
email-addrrsahelp[@]protonmail[.]com
MD5c5d712f82d5d37bb284acd4468ab3533Cring.exe; f7d270ca0f2b4d21830787431f881cd004b2eb102cc3048c6b4d69cb775511c8.bin
SHA-13426e8dcb104d9b01874498fb44c6e460228a9a0Cring.exe; f7d270ca0f2b4d21830787431f881cd004b2eb102cc3048c6b4d69cb775511c8.bin
SHA-256f7d270ca0f2b4d21830787431f881cd004b2eb102cc3048c6b4d69cb775511c8Cring.exe; f7d270ca0f2b4d21830787431f881cd004b2eb102cc3048c6b4d69cb775511c8.bin
SSDEEP384:asgE0J/RBKbpdqPnrjBCokjvPGumOiZ81eAl6CjUj:asgEMJwbK/X8AAl6LjCring.exe; f7d270ca0f2b4d21830787431f881cd004b2eb102cc3048c6b4d69cb775511c8.bin
email-addreternalnightmare[@]tutanota[.]com

Provenance

Allegato ufficiale CISA · 2025-02-18T19:14:27Z

SHA-512: e8573561411fb21c30e6e199de4c20c2071050022c6da837749dd8e94f08faa1fb8afcbc4ab927378c911601b5adc5dc69899cbe9d32f68c881e9133bb962a14

Questo allegato contiene 1 indicatori incompleti o non interpretabili, conservati nell'originale ma esclusi dall'export operativo. I valori mancanti non sono stati dedotti.

TipoIndicatore (non cliccabile)File
MD5db38ef2e3d4d8cb785df48f458b35090sock.txt
MD5625bd7275e1892eac50a22f8b4a6355disx.txt
SHA-10979b2202e650444ffe61d9762cb756e7cdd6bf0isx.txt
SHA-256e0821121726dbe78c6423af0f46b2e938acf8ce74d4674751af4030d84be972aisx.txt
SSDEEP49152:Jri7bgnq+Tk/hkYD168uq6StA66ztND3Tv82putV6Cl:Jr0mFk/hX1/6h9rQ8isx.txt
MD5a2fd181f57548c215ac6891d000ec6b9main.txt
SHA-192e529aefd28e6a32b0ab9ef2289d211abbe435dmain.txt
SHA-2564a324fc6ab18f552b8669404219ba4f16ad167c6e534b61f5bc7831534eb23a1main.txt
SSDEEP49152:IPSQZsb3bimRrb/TwvO90d7HjmAFd4A64nsfJnP1Q3Wq9+YgSlD4byD1CFe9c74G:J3bim3OIFF7n2PMYmain.txt
MD5ff52fdf84448277b1bc121f592f753c5sp.txt
MD50a5c4ad3ec240fbfd00bdc1d36bd54ebx86.log
MD5c3b8f6d102393b4542e9f951c9435255x86.log
SHA-10183cf7515729edddc070ed0d564222b1d1e76d6x86.log
SHA-2564e9bb2de5712e0fdb7270cce45af0afb089c44d4424aa7cf8ca98219ec45a9c1x86.log
SSDEEP24576:oZSlJ2VULwYcNRv/D3cX8rJDAhPCDWBl4Z6ZH6GjMRCDPx9UhvkqVaTEKUYD1I/l:ITcXna6ZHru15YD1nzDsRkOXkyN47xCx86.log
MD5ef6a213f59f3fbee2894bd6734bbaed2Locker.exe
MD5d1c5e7b8e937625891707f8b4b594314ElysiumO.exe
SHA-1f031bba881a735e45b757548b9b981cc2dcd87ecElysiumO.exe
SHA-256c8acd8e65b46c86d0d01e961358bc6ab9aec70f90a57829aa15e39add536b5c8ElysiumO.exe
SSDEEP768:YBMQI6dpTIAcU+fipHZIpryQBwGZKBaja+jUZbB1hIl:YKAIAJJp5IIQCGVja+wZbB1elElysiumO.exe
MD5c9e35b5c1dc8856da25965b385a26ec4ElysiumO.exe
MD529e44e8994197bdb0c2be6fc5dfc15c2ElysiumO.exe
MD5d9c019182d88290e5489cdf3b607f982Ghost.exe
MD534b3009590ec2d361f07cac320671410Ghost.exe
email-addrrainbowforever[@]skiff[.]com
email-addrghost1998[@]tutamail[.]com
email-addrr[.]heisler[@]skiff[.]com
email-addrgenesis1337[@]tutanota[.]com
email-addrsummerkiller[@]mailfence[.]com
email-addrlockhelp1998[@]skiff[.]com
email-addrkev1npt[@]tuta[.]io
email-addrfileunlock[@]onionmail[.]org
email-addrshadowghost[@]skiff[.]com
email-addrkellyreiff[@]tutanota[.]com
email-addrevilcorp[@]skiff[.]com
email-addrghostsbackup[@]skiff[.]com
email-addrretryit1998[@]tutamail[.]com
email-addrghosts1337[@]tuta[.]io
email-addrcrptbackup[@]skiff[.]com
email-addrretryit1998[@]mailfence[.]com
email-addrghosts1337[@]skiff[.]com
email-addrcringghost[@]skiff[.]com
email-addrghostbackup[@]skiff[.]com
email-addrasauribe[@]tutanota[.]com
email-addrrainbowforever[@]tutanota[.]com
email-addrrsacrpthelp[@]skiff[.]com
email-addrhsharada[@]skiff[.]com
MD5ac58a214ce7deb3a578c10b97f93d9c3pro.txt; iex.exe; iex.txt
SHA-144396e35b328247dafd23b4a26b9d69c0011f54apro.txt; iex.exe; iex.txt
SHA-2560500c9d0b91e62993447cdcf5f691092aff409eca24080ce149f34e48a0445e0pro.txt; iex.exe; iex.txt
SSDEEP49152:vSthBqV3933Mrb/TQvO90d7HjmAFd4A64nsfJkxw4d9WN0+YgSlD47zD1yRMV1r5:h3933vuIA1rYi0PMYpro.txt; iex.exe; iex.txt
email-addrshadowghosts[@]tutanota[.]com
email-addrjust4money[@]tutanota[.]com
email-addrsummerkiller[@]tutanota[.]com
email-addrd3svc[@]tuta[.]io
email-addrd3crypt[@]onionmail[.]org
email-addrsdghost[@]onionmail[.]org
email-addrfortihooks[@]protonmail[.]com
email-addrwebroothooks[@]tutanota[.]com
email-addrrsahelp[@]protonmail[.]com
MD5c5d712f82d5d37bb284acd4468ab3533Cring.exe; f7d270ca0f2b4d21830787431f881cd004b2eb102cc3048c6b4d69cb775511c8.bin
SHA-13426e8dcb104d9b01874498fb44c6e460228a9a0Cring.exe; f7d270ca0f2b4d21830787431f881cd004b2eb102cc3048c6b4d69cb775511c8.bin
SHA-256f7d270ca0f2b4d21830787431f881cd004b2eb102cc3048c6b4d69cb775511c8Cring.exe; f7d270ca0f2b4d21830787431f881cd004b2eb102cc3048c6b4d69cb775511c8.bin
SSDEEP384:asgE0J/RBKbpdqPnrjBCokjvPGumOiZ81eAl6CjUj:asgEMJwbK/X8AAl6LjCring.exe; f7d270ca0f2b4d21830787431f881cd004b2eb102cc3048c6b4d69cb775511c8.bin
email-addreternalnightmare[@]tutanota[.]com

Provenance

Allegato ufficiale CISA · 2025-02-18T19:14:31Z

SHA-512: 4ae95c99d46f09b232249cda7db130ca170130c022b425e292d1e557075915872064be4a6d65bb0be5aafe88156e2cd3b695ea15177a8f1408aed3cdb501e5d5

Source
CISA Cybersecurity Advisories
Publishing entity
CISA
Entity type
National authority
Area
North America · US
Original language
en · translation in preparation
Publication
19/02/2025 13:00
Sharing
TLP:CLEAR
MITRE ATT&CK
T1003, T1018, T1041, T1047, T1057, T1059.001, T1059.003, T1068, T1070.001, T1071.001, T1087.002, T1098, T1105, T1132.001, T1134.001, T1135, T1136.001, T1136.002, T1190, T1486, T1490, T1505.003, T1518, T1518.001, T1562.001, T1564.003, T1567.002, T1573
CVE
CVE-2018-13379, CVE-2010-2861, CVE-2009-3960, CVE-2021-34473, CVE-2021-34523, CVE-2021-31207, CVE-2019-0604, CVE-2020-1472, CVE-2014-1812, CVE-2017-0143, CVE-2017-0144
Classification
Critical
Group attributed by the source
Ghost (Cring)
Stated country
US
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Action indicated by the source

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Official technical references

Open the original source