Chinese Hackers Compromised Organizations in 70 Nations, Warn US Federal Agencies

5Mind. The Meme Platform
The Epoch Times Header

Companies are advised to constantly update their apps and software, and patch known network vulnerabilities to prevent such attacks.

A ransomware group called “Ghost” is exploiting the network vulnerabilities of various organizations to gain access to their systems, according to a joint advisory issued by multiple U.S. federal agencies.

“Beginning early 2021, Ghost actors began attacking victims whose internet-facing services ran outdated versions of software and firmware,” the Cybersecurity and Infrastructure Security Agency (CISA) said in the Feb. 19 joint advisory. “Ghost actors, located in China, conduct these widespread attacks for financial gain.”

The attacks have targeted schools and universities, government networks, critical infrastructure, technology and manufacturing companies, health care, and several small and mid-sized businesses.

“This indiscriminate targeting of networks containing vulnerabilities has led to the compromise of organizations across more than 70 countries, including organizations in China,” CISA, the FBI, and the Multi-State Information Sharing and Analysis Center said in the advisory.

Ghost actors are also associated with other names such as Cring, Crypt3r, HsHarada, Hello, Wickrme, Phantom, Rapture, and Strike.

The criminals use publicly available code to exploit “common vulnerabilities and exposures” of their targets to secure access to servers. They leverage vulnerabilities in servers running Adobe ColdFusion, Microsoft Exchange, and Microsoft SharePoint.

Threat actors use tools to “collect passwords and/or password hashes to aid them with unauthorized logins and privilege escalation or to pivot to other victim devices,” the warning read. Attackers typically spend only a few days on their target’s networks.

The advisory recommended that organizations patch known network vulnerabilities by applying “timely security updates” to firmware, software, and operating systems.

Organizations must train users to recognize phishing attempts, it said. Entities should identify, investigate, and issue alerts regarding any “abnormal network activity.”

“Maintain regular system backups that are known-good and stored offline or are segmented from source systems,” the advisory added.

“Ghost ransomware victims whose backups were unaffected by the ransomware attack were often able to restore operations without needing to contact Ghost actors or pay a ransom.”

By Naveen Athrappully

Read Full Article on TheEpochTimes.com

Contact Your Elected Officials
The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

The family fault line

The future of humanity rests not upon government, but with the family. A principle that is as bold as it is true and profound.

Media is an Arm of the DNC

Those on the conservative right have realized both television, Hollywood, and the web have been biased in favor of the left and their causes and positions.

When Narrative Replaces Law

When media abandons its responsibility to inform and chooses to provoke, it does not distort truth. It creates the very chaos it then pretends to lament.

Behind the Curtain

At times people sense something is wrong. Events seem disconnected, yet together form a pattern of irrational policies, cultural shifts, and baffling narratives.

The Sedition of Minnesota’s Walz and Frey

The death of 37 year old Renee Nicole Good was preventable. Responses of Democrats Walz and Frey are contemptable and possibly sedition.

Schools Increasingly Consider Rewarding Teachers for Results, Not Seniority

Across many states and hundreds of school districts, traditional teacher pay based on seniority is being replaced by merit and performance models.

Unlawful Assembly Declared at Minneapolis Protest, Arrests Made

Law enforcement officials arrested a handful of anti-ICE protesters in Minneapolis after they did not leave the area when unlawful assembly was declared.

Operation Salvo Leads to Arrest of 54 Individuals in New York City: DHS

Authorities have arrested 54 individuals in New York under Operation Salvo, operation launched following shooting of CBP officer, the DHS said in Jan. 9 statement.

Over 50 Percent of North Carolina Trucking Licenses Issued to Foreigners Are Illegal: Duffy

A review of non-domiciled commercial driver’s licenses granted in North Carolina found that 54% were issued illegally, DOT said in a statement on Jan. 8.

Trump Declares National Emergency to Shield Venezuelan Oil Revenues Held in US Custody

Trump signed an EO declaring a national emergency to block courts or private creditors from seizing Venezuelan oil revenues held in U.S. Treasury accounts.

Trump Directs Purchase of $200 Billion in Mortgage Bonds

President Trump on Thursday ‍said the United States will purchase $200 billion ‌in mortgage bonds, with the goal of bringing down housing costs.

Trump Says US Will Begin Land Strikes on Cartels in Mexico

President Donald Trump announced in an interview aired Jan. 8 that the United States would begin launching strikes on cartels in Mexico.

US Trade Deficit Narrows Sharply to Lowest Level Since 2009

The U.S. trade deficit fell sharply in October 2025, reaching its lowest level in 16 years, new Bureau of Economic Analysis data released Jan. 8 shows.
spot_img

Related Articles