Cring is a human-operated ransomware family targeting Windows systems. It encrypts selected files using AES and protects the encryption keys with an embedded 8,192-bit RSA public key. Before encryption, it stops services and terminates processes associated with databases, business applications, and backup software. It deletes backup files and directories to impede recovery, leaves ransom demands, and can remove itself through a batch script after encryption. Targets include documents, databases, archives, and virtual-machine disk images.
Cring operators gain access through insecure or compromised RDP services, valid accounts, and exploitation of internet-facing systems. Documented campaigns exploited CVE-2018-13379 in Fortinet FortiGate SSL VPN appliances to obtain VPN credentials and CVE-2010-2861 in Adobe ColdFusion servers. Operators use Mimikatz for credential theft and Cobalt Strike for command execution, lateral movement, and payload deployment. Their attack chains have also included web shells, scheduled-task persistence, PowerShell and CertUtil downloads, acquisition of domain administrator privileges, disabling endpoint protection, deletion of Volume Shadow Copies, and clearing event logs. These supporting activities are performed by operators and auxiliary tools rather than necessarily by the ransomware executable itself.
Cring has affected industrial enterprises in Europe, including an incident in which encryption of control servers temporarily halted an industrial process. Attacks have also affected finance and transportation organizations, with detections across Europe, the Middle East, Africa, the Americas, and Asia-Pacific. Documented intrusions have involved unidentified threat actors; no specific actor attribution is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Three minutes later, the attacker took advantage of CVE-2010-2861, a directory traversal vulnerability in ColdFusion that permits a remote user to retrieve files from web server directories that aren’t supposed to be available to the public.
The attackers exploited the CVE-2018-13379 vulnerability in FortiGate VPN servers to gain access to the enterprise’s network.
Next, the attacker appears to have exploited another vulnerability in ColdFusion, CVE-2009-3960, which permits a remote attacker to inject data through an abuse of ColdFusion’s XML handling protocols.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The Cring ransomware gains initial access either through unsecure or compromised RDP or valid accounts.
The ransomware can also get into the system through certain vulnerability exploits.. The abuse of the aforementioned Adobe ColdFusion flaw (CVE-2010-2861) to enter the system is a new development for the threat. In the past, Cring was also used to exploit a FortiGate VPN server vulnerability (CVE-2018-13379).
BAT files were used to download and execute the Cring ransomware on the other systems in the compromised network.
Citrix ADC maintains a vulnerable Perl script (newbm.pl) that, when accessed via HTTP POST request ... allows local operating system (OS) commands to execute. Attackers can use this functionality to upload/execute command and control (C2) software ... and gain unauthorized access to the OS.
Once Cring has been executed in the system, it disables services and processes that might hinder the ransomware’s encryption routine.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware deployed after compromise of an exposed Adobe ColdFusion 9 server; it was used to encrypt the server and other machines on the victim network, including folders containing VM disk images.
Rarely seen ransomware deployed after exploitation of an old Adobe ColdFusion 9 vulnerability.
Ransomware deployed approximately 79 hours after the initial compromise of an internet-facing ColdFusion server. The payload, named msp.exe, encrypted the server and folders containing virtual machine disk images after the attackers shut down the VMs and disabled endpoint protection. Several other network machines were rendered unusable. The attackers deleted Volume Shadow Copies and cleared event logs; the ransom note appeared on the Windows login screen.
Ransomware that gains access via compromised RDP, valid accounts, and exploited vulnerabilities; uses follow-on tooling for credential theft and lateral movement; disables services and processes, deletes backups, encrypts files, and deletes itself via a BAT file.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.