Fog is a ransomware family first observed in 2024 and associated with rapid, opportunistic intrusions that have notably affected organizations in the United States, especially education and recreation, while also appearing in broader enterprise ransomware activity. It has been linked to attacks against Windows environments and has also been reported in operations affecting virtualized infrastructure such as VMware and ESXi-adjacent backup environments. Fog has been deployed in incidents involving compromised VPN access, including SonicWall SSL VPN accounts, and in some cases exploitation of Veeam Backup & Replication vulnerabilities such as CVE-2024-40711. Reporting also links Fog activity to operators tracked in overlapping clusters and to distribution by Storm-0844, with some tradecraft overlap noted with Akira-related operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In August 2024 SonicWall published advisory SNWLID-2024-0015 for CVE-2024-40766. It is an improper access control vulnerability in SonicOS. CVSS 9.3. It affects the management interface and the SSLVPN service on Gen 5, Gen 6 and Gen 7 firewalls.
The vulnerability, CVE-2024-40711, was used as part of a threat activity cluster we named STAC 5881. Attacks leveraged compromised VPN appliances for access and used the VEEAM vulnerability to create a new local administrator account named “point”. Some cases in this cluster led to the deployment of Akira or Fog ransomware. | Some cases in this cluster led to the deployment of Akira or Fog ransomware. Fog emerged earlier this year, first seen in May.
CVE-2023-48365: Qlik Sense Enterprise HTTP Tunneling RCE (CVSS 9.9)
CVE-2024-21762: Fortinet FortiOS SSL VPN Out-of-Bounds Write RCE (CVSS 9.8)
CVE-2023-27997: Fortinet FortiOS SSL VPN Heap Buffer Overflow RCE - XORtigate (CVSS 9.8)
CVE-2025-23006: SonicWall SMA 1000 Pre-Auth Deserialization RCE (CVSS 9.8)
Referenced via: https://labs.watchtowr.com/by-executive-order-we-are-banning-blacklists-domain-level-rce-in-veeam-backup-replication-cve-2025-23120/ and multiple linked articles about Veeam RCE flaws.
Defenders should act now — ... patch CVE-2024-53704 (CVSS 9.8, CISA KEV) ... Exploitation Assessment ... CVE-2024-53704 ... Campaign Sessions 5 ... Confirm your SonicOS firmware is patched against CVE-2024-53704 (versions at or below 7.1.1-7058, 7.1.2-7019, or 8.0.0-8035 are vulnerable).
Fog ransomware accounts for another significant share, with some documented intrusions achieving full network encryption in under four hours.
Fog ransomware accounts for another significant share, with some documented intrusions achieving full network encryption in under four hours.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
public reporting will tie initial access in a consequential incident or bounded campaign to artifacts obtained through a separate, earlier edge-appliance exposure
atexec, Remote scheduled task, Scheduled Task events (4698)... In one engagement, attackers leveraged Active Directory Group Policy to distribute the ransomware payload as a scheduled task across domain-joined systems, ensuring simultaneous execution at scale.
public reporting will tie initial access in a consequential incident or bounded campaign to artifacts obtained through a separate, earlier edge-appliance exposure
A qualifying case must clear four gates: Previously exposed artifacts are successfully reused. The reuse enables initial access in a consequential incident or bounded campaign.
PsExec and direct access to administrative shares (ADMIN$, C$, etc.) remained present in some engagements... The most common approach involved executing the ransomware binary from a single compromised system — typically a domain controller or infrastructure server — and encrypting data on remote systems through administrative shares (ADMIN$, C$).
Some cases in this cluster led to the deployment of Akira or Fog ransomware... observed the deployment of a previously-undocumented ransomware called “Frag”. When encrypted, files are given a .frag extension.
Prior to encryption, attackers systematically targeted backup infrastructure and virtualization platforms to maximize impact and eliminate recovery options: Hypervisors (VMware ESXi, Hyper-V) – Destruction or encryption of virtual machines at the hypervisor level; Backup infrastructure (Veeam) – Access via compromised privileged accounts or exploitation of known Veeam vulnerabilities to delete or encrypt backup repositories.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware mentioned as leveraging a Veeam Backup & Replication (VBR) RCE vulnerability in attacks starting in October 2024.
Ransomware reported in intrusions leveraging SonicWall VPN access, with rapid progression to full network encryption in some cases.
Ransomware family observed in double-extortion incidents where data exfiltration preceded encryption.
Fog is a ransomware variant that targets organizations in the education and recreation sectors in the United States. It is deployed via compromised VPN credentials, uses common penetration testing and lateral movement tools, and encrypts files with .FOG or .FLOCKED extensions. It disables Windows Defender, deletes shadow copies, and leaves ransom notes, but there is no evidence of data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.