logo

Navigating Through The Fog

ID: c009e819-9ea6-548f-b0d2-c61f5fc8cbf1

STIX ID: report--c009e819-9ea6-548f-b0d2-c61f5fc8cbf1

Feed Name: The DFIR Report

Threat Score
75/100

Date Published: 2025-04-28

Date Updated: 2026-04-19

Author: editor

...
...

The DFIR Report’s Threat Intel Group identified an exposed web directory (194.48.154.79:80) in December 2024 containing tools and artifacts used by a ransomware affiliate likely tied to the Fog group; the directory hosted C2 components (Sliver), credential stealing and AD exploitation tools (DonPAPI, Certipy, Zer0dump, Pachine/noPac), a SonicWall VPN scanner with potentially compromised credentials, AnyDesk persistence automation, and victim data spanning multiple industries and countries, indicating an active, organized ransomware campaign leveraging credential theft, AD exploitation, lateral movement, and C2 infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.