Lost in the Fog: A New Ransomware Threat
ID: 71ccfe17-6929-5f47-b76c-f9c3713d0ad2
STIX ID: report--71ccfe17-6929-5f47-b76c-f9c3713d0ad2
Feed Name: Arctic Wolf
Date Published: 2024-06-04
Date Updated: 2026-07-26
Author: Stefan Hostetler, Steven Campbell, Christopher Prest, Connor Belfiore, Markus Neis, Joe Wedderspoon, Rick McQuown and Arctic Wolf Labs Team
Arctic Wolf Labs observed an emerging ransomware variant dubbed “Fog” deployed against US organizations—predominantly in the education sector—using compromised VPN credentials, credential stuffing and pass-the-hash to gain access, then leveraging PsExec, RDP/SMB to move laterally; the actors encrypted VM storage (appending .fog/.flocked), deleted Veeam/volume shadow backups, disabled Windows Defender, left uniform ransom notes, and the report contains technical analysis, TTP mappings, IoCs (hashes, filenames, IPs, hostnames) and detection opportunities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
