Lost in the Fog: A New Ransomware Threat
ID: 3cc99c18-e4c4-58c1-b6c4-625d8142025a
STIX ID: report--3cc99c18-e4c4-58c1-b6c4-625d8142025a
Feed Name: Arctic Wolf Blog
Arctic Wolf Labs analyzed a newly observed ransomware variant dubbed 'Fog' active in May 2024 against U.S. education and recreation sector victims, noting initial access via compromised VPN credentials, rapid VM-focused encryption, deletion of volume shadow copies, and the use of tools like PsExec, SharpShares, and Veeam-Get-Creds.ps1; the report includes technical analysis, IoCs (hashes, hostnames, IPs, filenames, extensions), TTP mapping to MITRE ATT&CK, and detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
