Skip to content

Fog

Fog is a ransomware family first observed in 2024 and associated with rapid, opportunistic intrusions that have notably affected organizations in the United States, especially education and recreation, while also appearing in broader enterprise ransomware activity.

Profile source: Mallory opens in a new tab

Fog

Family profile

Fog is a ransomware family first observed in 2024 and associated with rapid, opportunistic intrusions that have notably affected organizations in the United States, especially education and recreation, while also appearing in broader enterprise ransomware activity. It has been linked to attacks against Windows environments and has also been reported in operations affecting virtualized infrastructure such as VMware and ESXi-adjacent backup environments. Fog has been deployed in incidents involving compromised VPN access, including SonicWall SSL VPN accounts, and in some cases exploitation of Veeam Backup & Replication vulnerabilities such as CVE-2024-40711. Reporting also links Fog activity to operators tracked in overlapping clusters and to distribution by Storm-0844, with some tradecraft overlap noted with Akira-related operations.

Capabilities

  • Brute Force
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Initial Access
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance
  • Scanning

Operational record

54
Indicators
1
YARA rules
2
Ransom notes
6
Negotiations
2
Leak sites
0 available

Credential Theft

  • DonPAPI
  • Veeam-Get-Creds

Discovery Enum

  • Advanced Port Scanner
  • SharpShares
  • SoftPerfect NetScan

LOLBAS

  • PsExec

Networking

  • Powercat
  • Proxychains

Offsec

  • Certipy
  • Impacket
  • Metasploit
  • NetExec
  • Orpheus
  • Sliver
  • Zer0dump

RMM Tools

  • AnyDesk

Published indicators

Md5

53 total
  • da15ca8a6a316ee543ecc0cf4799700e
  • cff6c948bfede2c14590bd5daacd96ef
  • d16ec8c2dc42401f3acea469c128d981
  • 21c244771422cf24ef49cdaf2b437c12
  • f6359f375ae370e15bfef366f238ee15
  • a8c09a3ad7a8faab7be4d46bbec4e01a
  • 8b157ad42fa665d263904052f56a009b
  • 470a328ad3705d0c6866a48912a3f718
  • bcd51ee1df396f07af0b0a345a6dbaf4
  • 935d7db2557d62a55a23b6020d42351c

Exploited software

Vulnerabilities linked to Fog

10 CVEs

MITRE ATT&CK

Fog in ATT&CK

9 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.