Chinese Hackers Compromised Organizations in 70 Nations, Warn US Federal Agencies

The Epoch Times Header

Companies are advised to constantly update their apps and software, and patch known network vulnerabilities to prevent such attacks.

A ransomware group called “Ghost” is exploiting the network vulnerabilities of various organizations to gain access to their systems, according to a joint advisory issued by multiple U.S. federal agencies.

“Beginning early 2021, Ghost actors began attacking victims whose internet-facing services ran outdated versions of software and firmware,” the Cybersecurity and Infrastructure Security Agency (CISA) said in the Feb. 19 joint advisory. “Ghost actors, located in China, conduct these widespread attacks for financial gain.”

The attacks have targeted schools and universities, government networks, critical infrastructure, technology and manufacturing companies, health care, and several small and mid-sized businesses.

“This indiscriminate targeting of networks containing vulnerabilities has led to the compromise of organizations across more than 70 countries, including organizations in China,” CISA, the FBI, and the Multi-State Information Sharing and Analysis Center said in the advisory.

Ghost actors are also associated with other names such as Cring, Crypt3r, HsHarada, Hello, Wickrme, Phantom, Rapture, and Strike.

The criminals use publicly available code to exploit “common vulnerabilities and exposures” of their targets to secure access to servers. They leverage vulnerabilities in servers running Adobe ColdFusion, Microsoft Exchange, and Microsoft SharePoint.

Threat actors use tools to “collect passwords and/or password hashes to aid them with unauthorized logins and privilege escalation or to pivot to other victim devices,” the warning read. Attackers typically spend only a few days on their target’s networks.

The advisory recommended that organizations patch known network vulnerabilities by applying “timely security updates” to firmware, software, and operating systems.

Organizations must train users to recognize phishing attempts, it said. Entities should identify, investigate, and issue alerts regarding any “abnormal network activity.”

“Maintain regular system backups that are known-good and stored offline or are segmented from source systems,” the advisory added.

“Ghost ransomware victims whose backups were unaffected by the ransomware attack were often able to restore operations without needing to contact Ghost actors or pay a ransom.”

By Naveen Athrappully

Read Full Article on TheEpochTimes.com

The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

Columns

LGBTQ™ Roundup: Future Rainbow Holocaust Victim Preps for Road Warrior Scenario

LGBTQ™ Propaganda Roundup: Nip/tucking the latest social engineering fisted...

Who Owns Your Local Newspaper These Days?

George Soros is a big time funder of left-wing causes including newspapers and radio stations. “Whoever controls the media controls the mind.” – Jim Morrison.

Democratic Party Is In The Intensive Care Unit

It is such a toxic environment for Democrats today that ESPN sports commentator Stephen A. Smith is being touted as a presidential candidate in 2028.

Illinois Thinks Gov. J.B. Pritzker Sucks!

Illinois Thinks Gov. J.B. Pritzker Sucks! And there are plenty of yard signs sprinkled around the State of Illinois saying so.

Secession’s Hotel California

England’s King George III found out the hard way that the very genesis of the American ethos is running our own affairs liberated from bureaucratic control. 

News

Judge Blocks Education Department, OPM From Sharing Data With DOGE

A federal judge on Feb. 24 blocked two agencies from sharing sensitive information with employees of the Department of Government Efficiency (DOGE).

MSNBC cancels Joy Reid’s show as part of programming shakeup at liberal network

MSNBC is canceling Joy Reid’s The ReidOut to be replaced by show featuring Symone Sanders-Townsend, former spokesperson to VP Kamala Harris.

Trump Media, Rumble Ask US Court to Issue Restraining Order Against Brazilian Judge

Trump Media and Rumble asked US court to issue restraining order against Brazilian judge who ordered nationwide suspension of Rumble’s video service in Brazil.
00:01:22

Trump January 6 Indictment Articles

Read January 6 related articles about indictments against Former President Donald Trump.

From Prisoner to Pastor: Transformation of Ex-Detroit Mayor Freed by Trump

Hours before Trump left office in 2021, a prison guard swung open the door of Kilpatrick’s cell and announced: “Man, you’re getting out of here.”

Probe of Maine Education Department Initiated Over Men Competing in Women’s Sports

U.S. Dept of Education launched an investigation into the Maine Dept of Education over its approval of male participation in women’s sporting events.

Newsom Asks Congress for Nearly $40 Billion for Los Angeles Wildfire Aid

California Gov. Gavin Newsom asked Congress to approve nearly $40 billion in relief aid for the Los Angeles area after last month’s destructive wildfires.
spot_img

Related Articles

Popular Categories

MAGA Business Central