Cring is a human-operated Windows ransomware family active since at least late 2020 and also referred to by aliases including Crypt3r, Ghost, Phantom, and Vjiszy1lo. It has been observed targeting enterprise environments, including industrial, finance, and transportation organizations, with activity concentrated in EMEA but also seen in the Americas and APAC.
Cring operators commonly obtain initial access through exposed or compromised remote access services and exploitation of internet-facing vulnerabilities. Reported entry vectors include insecure or compromised RDP, use of valid accounts, exploitation of Fortinet FortiOS SSL VPN vulnerability CVE-2018-13379, and exploitation of legacy Adobe ColdFusion vulnerabilities including CVE-2010-2861. In intrusions involving ColdFusion, operators used web-shell access, scheduled tasks, PowerShell, WMIC, and Cobalt Strike to establish persistence, execute commands, and expand access.
Post-compromise activity includes credential theft using Mimikatz, acquisition of elevated privileges up to domain administrator, and lateral movement across the victim network using stolen credentials and Cobalt Strike. Operators have used Windows CertUtil and malicious scripts to retrieve additional payloads, impair defenses, and stage ransomware deployment to other systems. Observed defense-evasion measures include code injection, in-memory execution, deletion or overwriting of artifacts, disabling endpoint protections, clearing logs, and self-deletion after encryption.
Cring prepares systems for encryption by terminating services and processes that may lock files or interfere with encryption, including business application processes, and by deleting backups and Volume Shadow Copies to hinder recovery. It then encrypts files on compromised systems and, in some incidents, affected servers hosting virtualized workloads, causing operational disruption. At least one reported industrial intrusion temporarily interrupted an industrial process after control-related servers were encrypted.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...the attacker used fairly sophisticated techniques to conceal their files, inject code into memory, and cover their tracks... then to execute ransomware known as Cring on the server, and against other machines on the target’s network.
...the attacker used fairly sophisticated techniques to conceal their files, inject code into memory, and cover their tracks... then to execute ransomware known as Cring on the server, and against other machines on the target’s network.
In the past, Cring was also used to exploit a FortiGate VPN server vulnerability (CVE-2018-13379). | The Cring ransomware gains initial access either through unsecure or compromised RDP or valid accounts. The abuse of the aforementioned Adobe ColdFusion flaw (CVE-2010-2861) to enter the system is a new development for the threat.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The Cring ransomware gains initial access either through unsecure or compromised RDP or valid accounts.
The ransomware can also get into the system through certain vulnerability exploits.. The abuse of the aforementioned Adobe ColdFusion flaw (CVE-2010-2861) to enter the system is a new development for the threat. In the past, Cring was also used to exploit a FortiGate VPN server vulnerability (CVE-2018-13379).
BAT files were used to download and execute the Cring ransomware on the other systems in the compromised network.
Citrix ADC maintains a vulnerable Perl script (newbm.pl) that, when accessed via HTTP POST request ... allows local operating system (OS) commands to execute. Attackers can use this functionality to upload/execute command and control (C2) software ... and gain unauthorized access to the OS.
Once Cring has been executed in the system, it disables services and processes that might hinder the ransomware’s encryption routine.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware deployed after compromise of an exposed Adobe ColdFusion 9 server; it was used to encrypt the server and other machines on the victim network, including folders containing VM disk images.
Rarely seen ransomware deployed after exploitation of an old Adobe ColdFusion 9 vulnerability.
Ransomware that gains access via compromised RDP, valid accounts, and exploited vulnerabilities; uses follow-on tooling for credential theft and lateral movement; disables services and processes, deletes backups, encrypts files, and deletes itself via a BAT file.
Human-operated ransomware used to breach networks via vulnerable Fortinet SSL VPN servers, move laterally, steal credentials, deploy payloads across the network, encrypt files with RSA-8192 + AES-128, remove backups, kill processes, and drop ransom notes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.