Fog is a ransomware operation first observed in 2024 and active through at least 2026. It is generally tracked as a financially motivated extortion actor rather than a state-sponsored intrusion set. Reporting places its emergence around Q1–Q2 2024, with early activity heavily affecting U.S. higher education, and later victim claims spanning sectors including technology, education, manufacturing, and transportation. Fog has been associated with double-extortion operations in which data is stolen prior to encryption and victims are pressured through a leak site and negotiation portal. Fog commonly relies on valid-account access rather than bespoke stealth tradecraft for initial compromise. Multiple investigations have linked the group to the abuse of compromised VPN credentials and SonicWall SSL VPN access, with some intrusions occurring on appliances affected by CVE-2024-40766. Fog has also been linked to exploitation of Veeam Backup & Replication vulnerabilities, including CVE-2024-40711, consistent with the broader ransomware trend of targeting backup infrastructure to facilitate lateral movement, data theft, and destruction of recovery options. Public reporting also describes Fog as exploiting stolen credentials and supply-chain-related weaknesses. Observed post-compromise behavior includes rapid progression from access to impact, with some intrusions reaching full network encryption in under four hours. Tradecraft reported across Fog incidents includes use of external remote services and valid accounts for entry, credential theft, pass-the-hash, brute forcing, browser and directory credential extraction, account manipulation for persistence, RDP-based access, network and share enumeration, lateral movement over SMB and remote administration channels, disabling security controls, deletion of backups and shadow copies, and exfiltration using common third-party tools and cloud services. Fog operators have also been observed targeting virtualized environments and backup-related assets to maximize operational disruption. Malware analysis indicates Fog ransomware itself focuses on encryption while relying on separate tooling for exfiltration and persistence. Reported variants have encrypted broad file sets, including virtual machine disk files, and appended distinct extensions across campaigns. The operation uses ransom notes directing victims to a Tor-based negotiation site. Several assessments suggest Fog’s operators or affiliates display experience disproportionate to the group’s relative newness, and some reporting has proposed that it may have absorbed affiliates from BlackCat and LockBit. Blockchain and operational analysis has also identified links between Fog and other ransomware operations, particularly Akira and Frag, including shared laundering infrastructure. Those overlaps suggest ecosystem-level relationships or shared affiliates, but do not by themselves prove common leadership. Known associated names in reporting include Fog and FOG; no widely established sub-group taxonomy is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as part of prior intrusions involving SonicWall SSL VPN accounts; the content does not establish provenance of the credentials or focus primarily on Fog itself.
Conducting ransomware intrusions via exploitation of SonicWall SSLVPN access weaknesses, particularly CVE-2024-40766, alongside credential-based access and fast post-compromise activity.
Associated with exploitation of Veeam Backup & Replication vulnerabilities in ransomware operations.
Named as one of several ransomware operations weaponizing a critical Veeam Backup & Replication RCE flaw in attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.