Chinese Hackers Compromised Organizations in 70 Nations, Warn US Federal Agencies

5Mind. The Meme Platform
The Epoch Times Header

Companies are advised to constantly update their apps and software, and patch known network vulnerabilities to prevent such attacks.

A ransomware group called “Ghost” is exploiting the network vulnerabilities of various organizations to gain access to their systems, according to a joint advisory issued by multiple U.S. federal agencies.

“Beginning early 2021, Ghost actors began attacking victims whose internet-facing services ran outdated versions of software and firmware,” the Cybersecurity and Infrastructure Security Agency (CISA) said in the Feb. 19 joint advisory. “Ghost actors, located in China, conduct these widespread attacks for financial gain.”

The attacks have targeted schools and universities, government networks, critical infrastructure, technology and manufacturing companies, health care, and several small and mid-sized businesses.

“This indiscriminate targeting of networks containing vulnerabilities has led to the compromise of organizations across more than 70 countries, including organizations in China,” CISA, the FBI, and the Multi-State Information Sharing and Analysis Center said in the advisory.

Ghost actors are also associated with other names such as Cring, Crypt3r, HsHarada, Hello, Wickrme, Phantom, Rapture, and Strike.

The criminals use publicly available code to exploit “common vulnerabilities and exposures” of their targets to secure access to servers. They leverage vulnerabilities in servers running Adobe ColdFusion, Microsoft Exchange, and Microsoft SharePoint.

Threat actors use tools to “collect passwords and/or password hashes to aid them with unauthorized logins and privilege escalation or to pivot to other victim devices,” the warning read. Attackers typically spend only a few days on their target’s networks.

The advisory recommended that organizations patch known network vulnerabilities by applying “timely security updates” to firmware, software, and operating systems.

Organizations must train users to recognize phishing attempts, it said. Entities should identify, investigate, and issue alerts regarding any “abnormal network activity.”

“Maintain regular system backups that are known-good and stored offline or are segmented from source systems,” the advisory added.

“Ghost ransomware victims whose backups were unaffected by the ransomware attack were often able to restore operations without needing to contact Ghost actors or pay a ransom.”

By Naveen Athrappully

Read Full Article on TheEpochTimes.com

Contact Your Elected Officials
The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

Post-Epstein Document Dump: The Moment for Left-Right Populist Unity?

Claims that a powerful, lawless network of child abusers has captured major Western institutions are now asserted with unprecedented certainty.

When care leads to death

On December 12, Illinois legalize physician assisted suicide, rebranded under the soothing sounding banner of “medical aid in dying,” or MAID.

Two Big Game Halftime Show Options

During the Super Bowl this year there will be two halftime shows going on at the same time competing for viewers.

‘Fantasizing About the Caribbean Island’: A Leftist Demigod’s Epic Fall From Grace

I forever washed my hands of Noam Chomsky when he demanded that the unvaccinated be “isolated from society.”

Pride and Prejudice and the Modern Woman: What the Story Should Still Mean to Us Today

Why should Jane Austin's Pride and Prejudice be so influential? Because it upholds biblical precepts pertaining to purity, manhood and womanhood.

‘All-American Halftime Show’ Serves as Alternative to Super Bowl’s Bad Bunny, Green Day Performance

Dueling halftime performances will vie for the attention of viewers across the world at Super Bowl LX in Santa Clara, California, on Sunday night.

Pentagon to Cut Academic Ties With Harvard, Hegseth Says

Secretary of War Pete Hegseth said the Pentagon will cut all academic ties with Harvard, saying the university no longer meets military services needs.

Appeals Court Rejects Challenge to Trump’s Orders Curbing DEI

A federal appeals court turned away a challenge to President Trump’s EO ending so-called DEI programs in the federal government.

Nearly 2,000 Truckers Deemed Unfit Are Removed From American Roads

Nearly 2,000 truckers deemed unqualified to drive on U.S. roads have been removed, with arrests made and many vehicles placed out of service, DOT said.

Why Canada’s China Pivot Makes US Tariff Relief Harder

Analysts say Ottawa’s Beijing outreach is raising new security and trade concerns in Washington—making U.S. tariff relief even harder to secure.

Trump Lifts Biden-Era Restrictions on Commercial Fishing in Atlantic Marine Monument

President Trump revoked a prohibition on commercial fishing in the Northeast Canyons and Seamounts Marine National Monument.

US Unveils Interim Trade Framework With India, Drops Punitive Tariff

“The Interim trade framework between the US and India will represent a historic milestone in our countries’ partnership" countries said in a joint statement.

Trump Says He’s Still Looking ‘Seriously’ at Sending $2,000 Tariff Rebate Payments

Trump said in an interview that his administration is still considering sending out $2,000 payments to Americans derived from his tariffs.
spot_img

Related Articles