Cring — Ransomware Profile

Cring is a financially motivated ransomware operation that CISA and the FBI track under the combined designation "Ghost (Cring)", placing its operators in China. Kaspersky's ICS-CERT unit published a detailed public analysis in April 2021, covering a run of Q1 2021 intrusions in which the crew abused the FortiGate VPN directory-traversal flaw CVE-2018-13379 to break into industrial enterprises in European countries; Kaspersky notes the activity had already been flagged in a Swisscom CSIRT tweet. In at least one of those cases the encryption of servers running an industrial process forced that process to shut down temporarily. Sophos documented a separate intrusion in which the operators chained two long-patched Adobe ColdFusion 9 bugs — CVE-2010-2861 for directory traversal, then CVE-2009-3960 — against a Windows Server 2008 host, delivering the ransomware executable roughly 79 hours after the initial breach. The group has no single stable brand: CISA lists Crypt3r, Wickrme and HsHarada among the names associated with it. Its targeting is indiscriminate rather than selective, hitting organisations in more than 70 countries, and the FBI was still investigating Ghost/Cring incidents as recently as January 2025, so the family should be treated as active.

Also tracked as

Ghost (Cring), Crypt3r, Wickrme, HsHarada

Vendor research

Read the full analysis on IntelFusions