Chinese Hackers Compromised Organizations in 70 Nations, Warn US Federal Agencies

5Mind. The Meme Platform
The Epoch Times Header

Companies are advised to constantly update their apps and software, and patch known network vulnerabilities to prevent such attacks.

A ransomware group called “Ghost” is exploiting the network vulnerabilities of various organizations to gain access to their systems, according to a joint advisory issued by multiple U.S. federal agencies.

“Beginning early 2021, Ghost actors began attacking victims whose internet-facing services ran outdated versions of software and firmware,” the Cybersecurity and Infrastructure Security Agency (CISA) said in the Feb. 19 joint advisory. “Ghost actors, located in China, conduct these widespread attacks for financial gain.”

The attacks have targeted schools and universities, government networks, critical infrastructure, technology and manufacturing companies, health care, and several small and mid-sized businesses.

“This indiscriminate targeting of networks containing vulnerabilities has led to the compromise of organizations across more than 70 countries, including organizations in China,” CISA, the FBI, and the Multi-State Information Sharing and Analysis Center said in the advisory.

Ghost actors are also associated with other names such as Cring, Crypt3r, HsHarada, Hello, Wickrme, Phantom, Rapture, and Strike.

The criminals use publicly available code to exploit “common vulnerabilities and exposures” of their targets to secure access to servers. They leverage vulnerabilities in servers running Adobe ColdFusion, Microsoft Exchange, and Microsoft SharePoint.

Threat actors use tools to “collect passwords and/or password hashes to aid them with unauthorized logins and privilege escalation or to pivot to other victim devices,” the warning read. Attackers typically spend only a few days on their target’s networks.

The advisory recommended that organizations patch known network vulnerabilities by applying “timely security updates” to firmware, software, and operating systems.

Organizations must train users to recognize phishing attempts, it said. Entities should identify, investigate, and issue alerts regarding any “abnormal network activity.”

“Maintain regular system backups that are known-good and stored offline or are segmented from source systems,” the advisory added.

“Ghost ransomware victims whose backups were unaffected by the ransomware attack were often able to restore operations without needing to contact Ghost actors or pay a ransom.”

By Naveen Athrappully

Read Full Article on TheEpochTimes.com

Contact Your Elected Officials
The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

Twas the Night Before 3i/Atlas

And all through our Solar System, not an extraterrestrial alien was stirring according to today’s wisdom. But on Dec. 19. 2025, things could change.

Zach De Gregorio Calls Out Tim Pool!

A video on Wolves And Finance by Zach De Gregorio responded defensively to an earlier Tim Pool segment aired on the Timcast channel.

Rob Reiner’s Death Proves Trump Right, Again

“I believe Donald Trump will be the last president...

British Medical Journal Decries Racist Western Opposition to Female Genital Mutilation

In its “Journal of Medical Ethics” the British Medical Journal endorsed the tradition of female genital mutilation among certain North African cultures.

The Sacred Responsibility

From the beginning of time the female of every kind holds the sacred responsibility of continuing existence itself.

Man Suspected in Brown University Shooting Found Dead, Officials Say

A suspect in a fatal shooting at Brown University was found dead, officials announced. The man appears to have died from a self-inflicted gunshot wound.

US Indicts Over 70 Tren de Aragua Members in Nationwide Crackdown

DOJ announced multiple indictments against more than 70 members of Tren de Aragua in a nationwide crackdown on the foreign terrorist organization.

Stanford Study Pinpoints Cause of Vaccine-Linked Myocarditis and a Possible Fix

Myocarditis from COVID-19 vaccines is caused by two chemicals acting together, according to a new Stanford study published on Dec. 10.

Democrats Demand Vote on ACA Credits Before House Recesses for Holidays

House Democrats on Dec. 18 urged Speaker Mike Johnson to bring a bill extending Affordable Care Act tax credits to the House floor before the holiday recess.

Trump Gives Federal Workers 2 More Days Off: Dec. 24 and 26

President Donald Trump signed an executive order on Thursday closing the federal government on Dec. 24 and 26.

Trump Signs Executive Order to Pursue US Space Superiority

Hours after NASA’s new permanent administrator was sworn in, Trump signed an executive order advancing a policy of American dominance in outer space.

Trump Directs Administration to Reclassify Cannabis to Allow for Medical Research

President Trump signed an EO directing Attorney General Pam Bondi to expedite the reclassification of cannabis for the purpose of allowing medical research.

Trump Highlights Measures to Drive Down Costs in Prime-Time Address

President Trump told the nation his administration is prioritizing the American economy and reducing the cost of living during address from the White House on Dec. 17.
spot_img

Related Articles