Researchers reported that Fog ransomware is being deployed through a heavily obfuscated, multi-stage loader designed to frustrate analysis and bypass defenses. The initial loader uses large amounts of junk code, anti-sandbox and anti-debugging checks, and DLL unhooking before decrypting a second-stage shellcode that resolves APIs through hashing, reflectively loads an embedded DLL, and triggers its DLLRegisterServer export to launch the ransomware payload. Trend Micro also linked Fog activity to criminals claiming ties to DOGE, indicating an effort to brand or disguise the operation while expanding distribution.
The final Fog payload decrypts an internal JSON configuration and ransom note, creates a mutex, performs host reconnaissance, and attempts to stop selected processes and services before deleting shadow copies and encrypting files with a multithreaded routine. The ransom note says victims' data was both encrypted and exfiltrated, and it directs targets to Tor-based contact infrastructure, underscoring Fog's use of double-extortion tactics alongside layered evasion and execution techniques.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
A public malware analysis documented a Fog ransomware sample delivered through a loader that used anti-sandboxing, anti-debugging, DLL unhooking, second-stage shellcode, and a final DLL that encrypted files and claimed data exfiltration. The analysis also published hashes, mutex, configuration details, ransom-note contents, and reconnaissance behavior.
Trend Micro published research describing Fog ransomware being concealed within binary loaders and spread by cybercriminals claiming ties to DOGE. The report documents the malware’s loader-based delivery and broader campaign characteristics.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.