New Fog ransomware targets US education sector via breached VPNs
ID: 135fb9ac-b5f7-5274-95c1-66b1a2887e51
STIX ID: report--135fb9ac-b5f7-5274-95c1-66b1a2887e51
Feed Name: Bleeping Computer
Threat Score
Fog is a recently observed ransomware operation (discovered May 2024) that compromises VPN credentials to access U.S. educational networks, performs credential abuse (pass-the-hash, credential stuffing), disables Windows Defender, encrypts VM storage (VMDK) and other files using configurable extensions (.FOG/.FLOCKED), deletes backups (Veeam/object storage and shadow copies), and uses a Tor negotiation site for ransom and double-extortion demands.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
