Fog ransomware is a financially motivated ransomware and extortion operation first observed in May 2024. Known aliases include fog_ransomware and fog_ransomware_group. The group initially targeted organizations in the United States, particularly in education and recreation, and later expanded to additional sectors, including a financial institution in Asia. Fog is notable for combining conventional ransomware tradecraft with tooling and behaviors more often associated with espionage-oriented intrusions. Fog has used multiple initial access methods, including exploitation of SonicWall SSL VPN and Veeam Backup & Replication vulnerabilities, compromised credentials, and phishing. After access, the actors have conducted multi-stage intrusions involving privilege escalation, Active Directory enumeration, lateral movement, persistence, surveillance, and data theft before ransomware deployment. Reported tooling and techniques include use of PowerShell loaders, exploitation of a vulnerable driver for privilege escalation, pass-the-hash, PsExec- and SMBExec-style remote execution, and BloodHound for discovery and privilege-path analysis. A distinguishing feature of Fog operations is extensive use of legitimate and open-source tools for command and control, remote access, surveillance, and exfiltration. Observed tooling includes AnyDesk for remote access; GC2, Adaptix, and Stowaway for command and control or proxying; and Syteca employee-monitoring software for surveillance and credential theft or keylogging. The group has also used custom scripts to collect host, network, and geolocation data, and has attempted to remove surveillance tooling and related traces after use. In at least one case, the actors remained in a victim environment for roughly two weeks before deploying ransomware and even established additional persistence after encryption, an unusual pattern for ransomware incidents that suggests interest in sustained post-compromise access. Fog conducts double extortion: it steals data and encrypts systems, then threatens publication of stolen information through a dedicated leak site if victims do not pay. Exfiltration has involved common archiving and synchronization utilities and cloud-storage transfer workflows. The ransomware also deletes shadow copies to inhibit recovery and drops ransom notes directing victims to a negotiation portal. Some campaigns have used taunting or coercive messaging in ransom notes. Overall, Fog is characterized by defense evasion, blended criminal tradecraft, robust post-exploitation capability, and an operational profile that at times overlaps with espionage-style intrusion behavior.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Fog Ransomware is a cybercriminal group known for double-extortion ransomware attacks. They rapidly evolved from targeting education and recreation sectors in the US to a broad, global set of industries, including high-value financial institutions in Asia. Their operations are notable for APT-like behaviors, including multi-stage attacks, privilege escalation via driver exploits, extensive discovery, lateral movement, surveillance, and data exfiltration prior to encryption. They use a mix of custom and open-source tools, and their campaigns include both financial extortion and espionage elements.
Fog ransomware is known for targeting educational institutions in the U.S. and, more recently, financial institutions in Asia. The group uses a highly unusual toolset for ransomware operations, including legitimate employee monitoring software and open-source pentesting tools. Their operations include establishing persistence post-ransomware deployment, suggesting possible espionage motives in addition to financial extortion.
Fog ransomware is known for targeting organizations, notably the US education sector, and has recently attacked a financial institution in Asia. The group uses a mix of legitimate software and open source pentesting tools for espionage and ransomware deployment, suggesting dual motives of data theft and financial gain.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.