logo

Fog Ransomware Attacking US Organizations Leveraging Compromised VPN Credentials

ID: 933fdad0-01bd-536d-9d02-ac1e8fe958eb

STIX ID: report--933fdad0-01bd-536d-9d02-ac1e8fe958eb

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A new Fog ransomware variant has been observed since early May 2024 targeting U.S. education and recreation organizations; attackers gain initial access using compromised VPN credentials, perform pass-the-hash and credential-stuffing driven lateral movement (PsExec, RDP, SMB), disable Windows Defender, target Hyper-V and Veeam backup systems, encrypt files (extensions .FOG/.FLOCKED) after importing an RSA key, and remove volume shadow copies to thwart recovery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.