Ghost Ransomware — Victims, Campaigns & Activity

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
March 6, 2026
Last Seen
May 26, 2026

Ghost is a ransomware_group tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed March 6, 2026; most recent activity May 26, 2026.

Related Threat Clusters

  • Critical SQL Injection Vulnerability in Ghost CMS Exploited

    CVE-2026-26980 is a SQL Injection vulnerability affecting Ghost, a Node.js content management system, allowing unauthenticated attackers to perform arbitrary database reads. The flaw exists in the Content API's slug…

    2 articles · Updated May 24, 2026
  • FBI Networks Targeted in Suspicious Cybersecurity Incident

    The FBI has confirmed that its networks were targeted in a suspected cybersecurity incident, specifically affecting a sensitive system used for managing wiretaps and intelligence surveillance warrants. The bureau is…

    24 articles · Updated March 5, 2026
  • Rise of Drainer-as-a-Service: A New Threat to Cryptocurrency Holders

    Cryptocurrency theft operations have evolved into structured underground services known as Drainer-as-a-Service (DaaS). These services rely on social engineering tactics to lure victims to fake crypto-related websites,…

    2 articles · Updated May 21, 2026

Recent Intelligence Reports

  • SentinelOne Advisory — www.sentinelone.com · May 26, 2026
  • Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet — Bleepingcomputer · May 21, 2026
  • Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet — Bleepingcomputer · May 21, 2026
  • FBI wiretap system tapped by hackers — Csoonline · March 6, 2026

CVSS v3.1 Breakdown