Lost in the Fog: A New Ransomware Threat
ID: 718c54be-7e12-5ff2-8a8b-6ad8c8e842d9
STIX ID: report--718c54be-7e12-5ff2-8a8b-6ad8c8e842d9
Feed Name: Arctic Wolf
Date Published: 2024-06-04
Date Updated: 2026-07-26
Author: Stefan Hostetler, Steven Campbell, Christopher Prest, Connor Belfiore, Markus Neis, Joe Wedderspoon, Rick McQuown and Arctic Wolf Labs Team
### Executive Summary Arctic Wolf Labs observed a new ransomware variant named "Fog" active in May 2024 against US organizations (predominantly education), where threat actors used compromised VPN credentials, credential stuffing, and pass-the-hash to gain access, moved laterally with PsExec and RDP/SMB, disabled Windows Defender, encrypted VM storage (appending .fog/.flocked), deleted Veeam backups and volume shadow copies, and left ransom notes; the report includes technical analysis, TTP mappings, IoCs (hashes, IPs, filenames), and detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
