Fog is a ransomware operation first observed in 2024 and associated with fast-moving intrusions, credential-based access, and double-extortion activity. Reporting places its emergence in Q1–Q2 2024, with early campaigns heavily targeting higher education institutions in the United States. The operation has been assessed as likely drawing experienced personnel or affiliates from earlier ransomware ecosystems, including possible overlap with BlackCat and LockBit affiliate talent. Fog commonly gains initial access through valid or compromised VPN credentials and has repeatedly been linked to intrusions involving SonicWall SSL VPN accounts. It has also been associated with exploitation of SonicWall SonicOS vulnerability CVE-2024-40766 and Veeam Backup & Replication vulnerability CVE-2024-40711. In observed campaigns, Fog operators moved from access to full network encryption extremely quickly, in some cases in under four hours. Post-compromise activity includes reconnaissance, credential theft, privilege escalation, lateral movement, defense evasion, data exfiltration, and impact actions. Observed tradecraft includes use of common administrative and offensive tooling for network discovery and remote execution, abuse of pass-the-hash, password extraction from browsers and directory stores, brute forcing of user accounts, and use of RDP, SMB/admin shares, PsExec, Metasploit, reverse SSH shells, and other third-party tools to maintain access and spread. Operators have been observed disabling security controls, deleting backups and shadow copies, and targeting virtualized environments and backup infrastructure, including Veeam, to hinder recovery. Fog conducts double extortion, stealing data prior to encryption and threatening publication through a leak site if victims do not pay. Exfiltration has been carried out with third-party tools and cloud services, including commonly observed file-transfer utilities. Victim claims since 2025 indicate activity across technology, education, manufacturing, and transportation, while incident reporting also highlights a strong concentration on U.S. higher education. Fog has been linked to Frag and Akira through shared laundering infrastructure, suggesting ecosystem overlap, but it remains a distinct ransomware actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as part of prior intrusions involving SonicWall SSL VPN accounts; the content does not establish provenance of the credentials or focus primarily on Fog itself.
Conducting ransomware intrusions via exploitation of SonicWall SSLVPN access weaknesses, particularly CVE-2024-40766, alongside credential-based access and fast post-compromise activity.
Associated with exploitation of Veeam Backup & Replication vulnerabilities in ransomware operations.
Named as one of several ransomware operations weaponizing a critical Veeam Backup & Replication RCE flaw in attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.