| 2025-07-22 |
Joint Advisory Issued on Protecting Against Interlock Ransomware
This advisory highlights known Interlock ransomware indicators of compromise and tactics, techniques, and procedures identified through recent FBI investigations. Actions organizations can take today to mitigate Interlock ransomware threat activity include: Preventing initial access by implementing domain name system filtering and web access firewalls and training users to spot social engineering attempts.
|
CISA
FBI
HHS
|
| 2025-07-22 |
#StopRansomware: Interlock
Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Interlock Prevent initial access by implementing domain name system (DNS) filtering and web access firewalls, and training users to spot social engineering attempts.
|
CISA
FBI
HHS
NIST
|
| 2025-07-22 |
#StopRansomware: Interlock
Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Interlock Prevent initial access by implementing domain name system (DNS) filtering and web access firewalls, and training users to spot social engineering attempts.
|
CISA
FBI
HHS
|
| 2025-03-12 |
CISA and Partners Release Cybersecurity Advisory on Medusa Ransomware
This advisory provides tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), and detection methods associated with known Medusa ransomware activity. Medusa is a ransomware-as-a-service variant used to conduct ransomware attacks; as of December 2024, over 300 victims from critical infrastructure sectors have been impacted.
|
CISA
FBI
|
| 2025-03-12 |
#StopRansomware: Medusa Ransomware
CISA, FBI, and MS-ISAC warn that Medusa ransomware has targeted over 300 victims across critical infrastructure sectors since 2021 using a double-extortion model. Operators gain initial access via phishing and unpatched vulnerabilities, then encrypt systems and threaten to leak stolen data unless ransom is paid.
|
CISA
FBI
|
| 2025-03-12 |
#StopRansomware: Medusa Ransomware
Finally, the registry is modified to allow Remote Desktop connections: fDenyTSConnections /t REG_DWORD /d 0 /f Mimikatz has also been observed in use for Local Security Authority Subsystem Service (LSASS) dumping [T1003.001] to harvest credentials [TA0006] and aid lateral movement. Medusa actors install and use Rclone to facilitate exfiltration of data to the Medusa C2 servers [T1567.002] used by actors and affiliates.
|
CISA
FBI
|
| 2025-02-19 |
CISA and Partners Release Advisory on Ghost (Cring) Ransomware
Today, CISA—in partnership with the Federal Bureau of Investigation (FBI) and Multi-State Information Sharing and Analysis Center (MS-ISAC)—released a joint Cybersecurity Advisory, #StopRansomware: Ghost (Cring) Ransomware . This advisory provides network defenders with indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and detection methods associated with Ghost ransomware activity identified through FBI investigations.
|
CISA
FBI
|
| 2025-02-19 |
#StopRansomware: Ghost (Cring) Ransomware
Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Ghost
|
CISA
FBI
|
| 2025-02-19 |
#StopRansomware: Ghost (Cring) Ransomware
Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Ghost
|
CISA
FBI
|
| 2024-08-29 |
CISA and Partners Release Advisory on RansomHub Ransomware
Today, CISA—in partnership with the Federal Bureau of Investigation (FBI), Multi-State Information Sharing and Analysis Center (MS-ISAC), and Department of Health and Human Services (HHS)—released a joint Cybersecurity Advisory, #StopRansomware: RansomHub Ransomware .
|
CISA
FBI
HHS
|
| 2024-08-29 |
#StopRansomware: RansomHub Ransomware
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. An improper neutralization of special elements used in an SQL command (SQL injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and FortiClientEMS 7.0.1 through 7.0.
|
CISA
FBI
HHS
|
| 2024-05-10 |
CISA and Partners Release Advisory on Black Basta Ransomware
Today, CISA, in partnership with the Federal Bureau of Investigation (FBI), the Department of Health and Human Services (HHS), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) released joint Cybersecurity Advisory (CSA) #StopRansomware: Black Basta to provide cybersecurity defenders tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) used by known Black Basta ransomware affiliates and identified thr…
|
CISA
CSA
FBI
HHS
|
| 2024-05-10 |
#StopRansomware: Black Basta
These #StopRansomware advisories include recently and historically observed tactics, Install updates for operating techniques, and procedures (TTPs) and indicators of systems, software, and firmware compromise (IOCs) to help organizations protect against as soon as they are released.
|
CISA
FBI
HHS
|
| 2024-05-01 |
CISA and Partners Release Fact Sheet on Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity
This fact sheet provides information and mitigations associated with cyber operations conducted by pro-Russia hacktivists who seek to compromise industrial control systems (ICS) and small-scale operational technology (OT) systems in North American and European critical infrastructure sectors, including Water and Wastewater Systems, Dams, Energy, and Food and Agriculture Sectors.
|
CCCS
CISA
NCSC-UK
USDA
|
| 2024-05-01 |
Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity
|
CCCS
CISA
DOE
EPA
FBI
NCSC-UK
NSA
USDA
|
| 2024-03-21 |
CISA, FBI, and MS-ISAC Release Update to Joint Guidance on Distributed Denial-of-Service Techniques
The guidance now includes detailed insight into three different types of DDoS techniques: Volumetric, attacks aiming to consume available bandwidth. Protocol, attacks which exploit vulnerabilities in network protocols.
|
CISA
FBI
|
| 2024-02-29 |
CISA, FBI, and MS-ISAC Release Advisory on Phobos Ransomware
Structured as a ransomware as a service (RaaS) model, Phobos ransomware actors have targeted entities including municipal and county governments, emergency services, education, public healthcare, and critical infrastructure to successfully ransom several million in U.S. dollars. This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA
FBI
|
| 2024-02-29 |
#StopRansomware: Phobos Ransomware
INDICATORS OF COMPROMISE (IOCs) See Table 1 through 6 for IOCs obtained from CISA and the FBI investigations from September through Table 1: Associated Phobos Domains Table 2: Observed Phobos Shell Commands vssadmin delete shadows /all /quiet [T1490] netsh advfirewall set currentprofile state off netsh firewall set opmode mode=disable [T1562.004] bcdedit /set {default} bootstatuspolicy ignoreallfailures [T1547.
|
CISA
FBI
|
| 2024-02-29 |
CISA and Partners Release Advisory on Threat Actors Exploiting Ivanti Connect Secure and Policy Secure Gateways Vulnerabilities
Additionally, the advisory describes two key CISA findings: The Ivanti Integrity Checker Tool is not sufficient to detect compromise due to the ability of threat actors to deceive it, and A cyber threat actor may be able to gain root-level persistence despite the victim having issued factory resets on the Ivanti device.
|
ASD/ACSC
CCCS
CISA
FBI
NCSC-NZ
NCSC-UK
|
| 2024-02-29 |
Threat Actors Exploit Multiple Vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways
CISA and authoring organizations appreciate the cooperation of Volexity, Ivanti, Mandiant and other industry partners in the development of this advisory and ongoing incident response activities. Authoring organizations: Of particular concern, the authoring organizations and industry partners have determined that cyber threat actors are able to deceive Ivanti’s internal and external Integrity Checker Tool (ICT), resulting in a failure to detect c…
|
ASD/ACSC
CCCS
CISA
FBI
NCSC-NZ
NCSC-UK
|
| 2024-02-15 |
CISA and MS-ISAC Release Advisory on Compromised Account Used to Access State Government Organization
Following an incident response assessment of a state government organization’s network environment, analysis confirmed compromise through network administrator credentials of a former employee. This allowed the threat actor to successfully authenticate to an internal virtual private network (VPN) access point.
|
CISA
|