logo

FOG Ransomware Group Leaks Source Code of Three French Organizations

ID: 9b1e84d6-953e-51e4-bd06-0634c20c5869

STIX ID: report--9b1e84d6-953e-51e4-bd06-0634c20c5869

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2025-02-14

Date Updated: 2026-04-13

Author: AnuPriya

...
...

**Executive summary:** The FOG ransomware group publicly leaked stolen data and source code from three French organizations (Omydoo, Ayomi.fr, ADULLACT) after unsuccessful ransom negotiations; the group uses RDP brute-force and compromised VPN credentials for access, exfiltrates data with tools like MEGAsync and FileZilla, encrypts files (appending .fog/.flocked), disables Defender and deletes backups, and employs double-extortion with average demands around $220,000—underscoring significant operational and reputational risk to victims and the need for stronger defensive measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.