Chinese Hackers Compromised Organizations in 70 Nations, Warn US Federal Agencies

The Epoch Times Header

Companies are advised to constantly update their apps and software, and patch known network vulnerabilities to prevent such attacks.

A ransomware group called โ€œGhostโ€ is exploiting the network vulnerabilities of various organizations to gain access to their systems, according to a joint advisory issued by multiple U.S. federal agencies.

โ€œBeginning early 2021, Ghost actors began attacking victims whose internet-facing services ran outdated versions of software and firmware,โ€ the Cybersecurity and Infrastructure Security Agency (CISA) said in the Feb. 19 joint advisory. โ€œGhost actors, located in China, conduct these widespread attacks for financial gain.โ€

The attacks have targeted schools and universities, government networks, critical infrastructure, technology and manufacturing companies, health care, and several small and mid-sized businesses.

โ€œThis indiscriminate targeting of networks containing vulnerabilities has led to the compromise of organizations across more than 70 countries, including organizations in China,โ€ CISA, the FBI, and the Multi-State Information Sharing and Analysis Center said in the advisory.

Ghost actors are also associated with other names such as Cring, Crypt3r, HsHarada, Hello, Wickrme, Phantom, Rapture, and Strike.

The criminals use publicly available code to exploit โ€œcommon vulnerabilities and exposuresโ€ of their targets to secure access to servers. They leverage vulnerabilities in servers running Adobe ColdFusion, Microsoft Exchange, and Microsoft SharePoint.

Threat actors use tools to โ€œcollect passwords and/or password hashes to aid them with unauthorized logins and privilege escalation or to pivot to other victim devices,โ€ the warning read. Attackers typically spend only a few days on their targetโ€™s networks.

The advisory recommended that organizations patch known network vulnerabilities by applying โ€œtimely security updatesโ€ to firmware, software, and operating systems.

Organizations must train users to recognize phishing attempts, it said. Entities should identify, investigate, and issue alerts regarding any โ€œabnormal network activity.โ€

โ€œMaintain regular system backups that are known-good and stored offline or are segmented from source systems,โ€ the advisory added.

โ€œGhost ransomware victims whose backups were unaffected by the ransomware attack were often able to restore operations without needing to contact Ghost actors or pay a ransom.โ€

Byย Naveen Athrappully

Read Full Article on TheEpochTimes.com

The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

Columns

How Legal Immigration Is Keeping Farms Afloat

The H-2A visa program is an example of how legal immigration can supply labor in America, but farmers say reform is needed.

Trumpโ€™s EO to Reduce Drug Prices Explained

Trump signed an Executive Order to bring the prices Americans pay for prescription drugs in line with those paid by other nations around the world.

Parents of Autistic Children Weigh In on RFK Jr.โ€™s Plan to Find the Cause

โ€˜The bottom line is we want the truth. We want safe products for our kids,โ€™ said an Ohio dad with an autistic child.

Fighting the Idiocracy

Despite our country's noble efforts to defend freedom and liberty across the globe we now find ourselves defending democracy against idiocracy.

Recent Sun Activity Could Trigger Major Earthquakes

A number of scientists around the world are sharing concerns about an imminent global seismic event.

News

Supreme Court Wrestles With Nationwide Injunctions in Birthright Citizenship Case

Supreme Court grappled with how far federal judges could go in issuing sweeping blocks on policies such as Trumpโ€™s order restricting birthright citizenship.

Lawsuit Alleges Musk, Election PAC Failed to Pay Swing State Petition Signers

Lawsuit filed against Musk and his PAC accuses them of failing to pay registered voters in swing states for signing petition supporting candidate Trump.

Trump Weighs In on Supreme Court Case Involving Birthright Citizenship

President Trump weighed in on the U.S. Supreme Court hearing arguments in a case involving his order to limit birthright citizenship.

DOJ Charges High-Ranking Sinaloa Cartel Suspects With โ€˜Narco-Terrorismโ€™

Feds charged alleged leaders of Sinaloa cartelโ€™s Beltran Leyva Organization with narco-terrorism, terrorism support, and international drug trafficking.

Judge Orders HHS to Restore Jobs in Health Monitoring Program for West Virginia Coal Miners

West Virginia federal judge ordered HHS to reverse terminations of nearly 200 workers who oversee a health monitoring program for coal miners

Trump Admin Urges Supreme Court to Permit DOGE Access to Social Security Records

The DOJ urged the Supreme Court on May 13 to let the DOGE have access to Social Security data after lower courts blocked that access.

Deported Mother Who Took 2-Year-Old US Citizen Child With Her Drops Lawsuit Against Trump Admin

Lawsuit against Trump admin alleging it deported an illegal immigrant and her 2-year-old U.S. citizen child to Honduras without due process is being dropped.

Federal Judge Says Trumpโ€™s Invocation of Alien Enemies Act Was Legal

Federal judge in PA has ruled that President Trump validly invoked the Alien Enemies Act as part of an effort to deport Venezuelan gang members.
spot_img

Related Articles