logo

New Fog ransomware targets US education sector via breached VPNs

ID: 135fb9ac-b5f7-5274-95c1-66b1a2887e51

STIX ID: report--135fb9ac-b5f7-5274-95c1-66b1a2887e51

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-06-06

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Fog is a recently observed ransomware operation (discovered May 2024) that compromises VPN credentials to access U.S. educational networks, performs credential abuse (pass-the-hash, credential stuffing), disables Windows Defender, encrypts VM storage (VMDK) and other files using configurable extensions (.FOG/.FLOCKED), deletes backups (Veeam/object storage and shadow copies), and uses a Tor negotiation site for ransom and double-extortion demands.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.