logo

Lost in the Fog: A New Ransomware Threat

ID: 71ccfe17-6929-5f47-b76c-f9c3713d0ad2

STIX ID: report--71ccfe17-6929-5f47-b76c-f9c3713d0ad2

Feed Name: Arctic Wolf

Threat Score
75/100

Date Published: 2024-06-04

Date Updated: 2026-07-26

Author: Stefan Hostetler, Steven Campbell, Christopher Prest, Connor Belfiore, Markus Neis, Joe Wedderspoon, Rick McQuown and Arctic Wolf Labs Team

...
...

Arctic Wolf Labs observed an emerging ransomware variant dubbed “Fog” deployed against US organizations—predominantly in the education sector—using compromised VPN credentials, credential stuffing and pass-the-hash to gain access, then leveraging PsExec, RDP/SMB to move laterally; the actors encrypted VM storage (appending .fog/.flocked), deleted Veeam/volume shadow backups, disabled Windows Defender, left uniform ransom notes, and the report contains technical analysis, TTP mappings, IoCs (hashes, filenames, IPs, hostnames) and detection opportunities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.