Fog ransomware is a Windows-targeting double-extortion ransomware operation first documented in 2024. It encrypts victim data while also stealing sensitive information to increase pressure on victims through threatened public disclosure. Early activity was associated with attacks on educational institutions in the United States, and later reporting linked Fog to broader targeting across sectors including finance, technology, manufacturing, transportation, healthcare, retail, business services, and energy, with activity observed beyond the U.S., including in Asia and Turkey.
Fog operators have used multiple initial access methods. Reported intrusion vectors include compromised VPN credentials, exploitation of SonicWall SSL VPN and Veeam Backup & Replication vulnerabilities including CVE-2024-40766 and CVE-2024-40711, and phishing emails carrying archive attachments that launch multi-stage PowerShell infection chains. In observed email-delivered campaigns, staged scripts downloaded additional components used for ransomware deployment, reconnaissance, data theft, and privilege escalation.
Operationally, Fog has shown a more expansive post-compromise tradecraft than many commodity ransomware families. Reported activity includes reconnaissance and Active Directory enumeration, privilege escalation through abuse of a vulnerable Intel network adapter diagnostic driver, lateral movement using remote execution and SMB-based tooling, persistence via custom Windows services and watchdog mechanisms, and command-and-control through open-source frameworks and legitimate remote-access software. In some incidents, operators reportedly remained in victim environments for extended periods before encryption and even established persistence after ransomware deployment, behavior that has led some researchers to assess possible espionage objectives alongside financial extortion.
Fog has also been associated with surveillance and information-theft activity through use of employee-monitoring software and custom scripts that collect host, network, and geolocation data. For exfiltration, operators have used common archiving, synchronization, and cloud-transfer utilities. Recovery is hindered by deletion of shadow copies. Encrypted files have been observed with Fog-related extensions, and ransom notes direct victims to negotiate while threatening publication of stolen data on a leak site. Some campaigns used DOGE-themed messaging and coercive instructions intended to spread the malware further. Overall, Fog is notable for combining ransomware monetization with sustained post-exploitation, data theft, and defense-evasion tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...another VBR RCE flaw (CVE-2024-40711) disclosed in September is now being exploited to deploy Frag ransomware. The same vulnerability was also used... in Akira and Fog ransomware attacks...
13 distinct techniques documented for this family, organized by ATT&CK tactic.
When clicked, this file runs a PowerShell command to download a malicious script named stage1.ps1. “The downloaded PowerShell script performs a multi-stage operation, retrieving a ransomware loader (cwiper.exe), ktool.exe and other PowerShell scripts,” the report explains.
The content is a set of references repeatedly describing “critical RCE” and “code execution flaws” in Veeam Backup & Replication and Veeam Service Provider Console, and noting active exploitation and ransomware use (e.g., “new Veeam vulnerabilities expose backup servers to RCE attacks”, “Veeam patches critical vulnerability…”, “CISA alert active exploitation…”, “Akira and Fog ransomware now exploiting critical Veeam RCE flaw”).
It collects data such as IPv4 gateway IP, MAC address, geolocation data (using the Wigle API), hardware configuration, and system identifiers.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Fog Ransomware is a sophisticated double-extortion ransomware operation first observed in May 2024. It combines data encryption with exfiltration, threatening to leak stolen data if the ransom is not paid. The group employs advanced tactics, including APT-like espionage, privilege escalation via driver exploits, multi-stage PowerShell loaders, and extensive use of legitimate and open-source tools for persistence, lateral movement, and data exfiltration. It targets a wide range of industries and demonstrates a high level of operational maturity.
Fog Ransomware is a double extortion ransomware strain first identified in April 2024. It targets education and finance sectors, gaining initial access via compromised VPN credentials, escalating privileges, and moving laterally using tools like PsExec and Advanced Port Scanner. It encrypts files, deletes backups, and exfiltrates data for extortion, threatening to leak stolen data on its dark web site if ransoms are not paid.
Fog ransomware is a ransomware strain first observed in May 2024, known for targeting educational institutions and later expanding to other sectors such as finance. It is notable for its use of unusual toolsets, including legitimate employee monitoring software and open-source pentesting tools, and for establishing persistence even after ransomware deployment, suggesting possible espionage motives in addition to financial extortion.
FOG ransomware is a ransomware family that encrypts files, appends a .flocked extension, and drops a ransom note with DOGE-themed content. It is distributed via phishing emails with ZIP attachments containing disguised LNK files that execute PowerShell scripts to download and run the ransomware loader. The malware includes privilege escalation, system information exfiltration, sandbox evasion, and directs victims to pay ransom via a Monero wallet. It has targeted multiple industries and is capable of spreading laterally within networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.