Fog is a Windows ransomware family first observed in May 2024 and associated with financially motivated, rapid network-encryption and double-extortion intrusions. Early activity disproportionately affected U.S. education and recreation organizations, while subsequent incidents affected a broader range of sectors and geographies. Operators have commonly obtained initial access through compromised VPN accounts, including SonicWall SSL VPN access; Fog has also been deployed following exploitation of Veeam Backup & Replication vulnerability CVE-2024-40711. Reporting has linked Fog distribution to Storm-0844, an activity cluster also associated with Akira deployments.
Fog affiliates conduct reconnaissance, harvest credentials, move laterally through RDP, SMB administrative shares, PsExec, WMI, and scheduled tasks, and target backup and virtualized infrastructure. Observed operations have used pass-the-hash, credential stuffing, browser and directory-service credential extraction, and tools for network and share enumeration. They may exfiltrate data using third-party utilities and cloud services before encryption, then threaten public disclosure to pressure victims.
The ransomware disables security controls, stops selected processes and services, deletes volume shadow copies and backup data, and encrypts a broad range of files, including virtual-machine storage. It uses a configurable, multithreaded encryption implementation and creates ransom notes for victim negotiation. Analyzed Fog delivery chains have incorporated anti-sandbox and anti-debugging checks, API resolution, shellcode staging, reflective DLL loading, and attempts to remove endpoint-security hooks. Fog primarily targets Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In August 2024 SonicWall published advisory SNWLID-2024-0015 for CVE-2024-40766. It is an improper access control vulnerability in SonicOS. CVSS 9.3. It affects the management interface and the SSLVPN service on Gen 5, Gen 6 and Gen 7 firewalls.
The vulnerability, CVE-2024-40711, was used as part of a threat activity cluster we named STAC 5881. Attacks leveraged compromised VPN appliances for access and used the VEEAM vulnerability to create a new local administrator account named “point”. Some cases in this cluster led to the deployment of Akira or Fog ransomware. | Some cases in this cluster led to the deployment of Akira or Fog ransomware. Fog emerged earlier this year, first seen in May.
CVE-2023-48365: Qlik Sense Enterprise HTTP Tunneling RCE (CVSS 9.9)
CVE-2024-21762: Fortinet FortiOS SSL VPN Out-of-Bounds Write RCE (CVSS 9.8)
CVE-2023-27997: Fortinet FortiOS SSL VPN Heap Buffer Overflow RCE - XORtigate (CVSS 9.8)
CVE-2025-23006: SonicWall SMA 1000 Pre-Auth Deserialization RCE (CVSS 9.8)
Referenced via: https://labs.watchtowr.com/by-executive-order-we-are-banning-blacklists-domain-level-rce-in-veeam-backup-replication-cve-2025-23120/ and multiple linked articles about Veeam RCE flaws.
Defenders should act now — ... patch CVE-2024-53704 (CVSS 9.8, CISA KEV) ... Exploitation Assessment ... CVE-2024-53704 ... Campaign Sessions 5 ... Confirm your SonicOS firmware is patched against CVE-2024-53704 (versions at or below 7.1.1-7058, 7.1.2-7019, or 8.0.0-8035 are vulnerable).
Fog ransomware accounts for another significant share, with some documented intrusions achieving full network encryption in under four hours.
Fog ransomware accounts for another significant share, with some documented intrusions achieving full network encryption in under four hours.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
public reporting will tie initial access in a consequential incident or bounded campaign to artifacts obtained through a separate, earlier edge-appliance exposure
atexec, Remote scheduled task, Scheduled Task events (4698)... In one engagement, attackers leveraged Active Directory Group Policy to distribute the ransomware payload as a scheduled task across domain-joined systems, ensuring simultaneous execution at scale.
public reporting will tie initial access in a consequential incident or bounded campaign to artifacts obtained through a separate, earlier edge-appliance exposure
A qualifying case must clear four gates: Previously exposed artifacts are successfully reused. The reuse enables initial access in a consequential incident or bounded campaign.
PsExec and direct access to administrative shares (ADMIN$, C$, etc.) remained present in some engagements... The most common approach involved executing the ransomware binary from a single compromised system — typically a domain controller or infrastructure server — and encrypting data on remote systems through administrative shares (ADMIN$, C$).
Some cases in this cluster led to the deployment of Akira or Fog ransomware... observed the deployment of a previously-undocumented ransomware called “Frag”. When encrypted, files are given a .frag extension.
Prior to encryption, attackers systematically targeted backup infrastructure and virtualization platforms to maximize impact and eliminate recovery options: Hypervisors (VMware ESXi, Hyper-V) – Destruction or encryption of virtual machines at the hypervisor level; Backup infrastructure (Veeam) – Access via compromised privileged accounts or exploitation of known Veeam vulnerabilities to delete or encrypt backup repositories.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware associated with WMI, remote scheduled-task execution, RDP movement, and SMB staging.
Ransomware mentioned as leveraging a Veeam Backup & Replication (VBR) RCE vulnerability in attacks starting in October 2024.
Ransomware reported in intrusions leveraging SonicWall VPN access, with rapid progression to full network encryption in some cases.
Ransomware family observed in double-extortion incidents where data exfiltration preceded encryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.