'Fog' Ransomware Rolls in to Target Education, Recreation Sectors
ID: 4270cfce-36f2-5d9c-94be-22ce657f9819
STIX ID: report--4270cfce-36f2-5d9c-94be-22ce657f9819
Feed Name: Dark Reading
Threat Score
Arctic Wolf researchers identified a new ransomware group called “Fog” conducting short, quick-pay ransomware attacks (May 2–23) that target virtualized environments by using stolen VPN credentials and administrator account compromises to access Hyper‑V and Veeam-protected Windows servers; the group encrypts data without exfiltration or leak-site/double-extortion behavior and has predominantly hit U.S. education organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
