Fog Ransomware Targets U.S. Organizations via Compromised VPN Credentials
ID: 7ee8d768-b3bc-5451-bdbc-666670e54599
STIX ID: report--7ee8d768-b3bc-5451-bdbc-666670e54599
Feed Name: GBHackers
Threat Score
Arctic Wolf Labs identified a new ransomware variant dubbed “Fog” active in May 2024 against US education and recreation sectors using compromised VPN credentials; attackers performed privilege escalation, lateral movement (RDP/SMB/PsExec), disabled defenses, encrypted VMs/backups (extensions .FOG/.FLOCKED), and deleted shadow copies, with several IOCs (SHA1s, IP, filenames) and a JSON-configured encryptor observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
