logo

Fog Ransomware Targets U.S. Organizations via Compromised VPN Credentials

ID: 7ee8d768-b3bc-5451-bdbc-666670e54599

STIX ID: report--7ee8d768-b3bc-5451-bdbc-666670e54599

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-09

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Arctic Wolf Labs identified a new ransomware variant dubbed “Fog” active in May 2024 against US education and recreation sectors using compromised VPN credentials; attackers performed privilege escalation, lateral movement (RDP/SMB/PsExec), disabled defenses, encrypted VMs/backups (extensions .FOG/.FLOCKED), and deleted shadow copies, with several IOCs (SHA1s, IP, filenames) and a JSON-configured encryptor observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.