'Fog' Hackers Troll Victims With DOGE Ransom Notes
ID: c722cd32-9edb-5b45-b25c-19dd25ff46bc
STIX ID: report--c722cd32-9edb-5b45-b25c-19dd25ff46bc
Feed Name: Dark Reading
Trend Micro analyzed active Fog ransomware campaigns that begin with phishing ZIPs containing malicious LNK files which execute PowerShell to download a ransomware downloader, system-harvesting scripts, lateral-movement tools, and display DOGE-themed ransom notes; operators have shifted toward double-extortion with data theft and a leak site. Researchers and other vendors report around 100 victims since January and 173 detections since June 2024 across technology, manufacturing, education, and transportation sectors, and have published IoCs and standard mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
