logo

Dark Web Profile: Fog Ransomware

ID: ae1e8edc-7c69-5b45-b5c9-7b27265dc8dc

STIX ID: report--ae1e8edc-7c69-5b45-b5c9-7b27265dc8dc

Feed Name: SOCRadar Blog

Threat Score
75/100

Date Published: 2025-02-13

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Fog Ransomware (observed Apr–May 2024) is a double-extortion ransomware variant targeting primarily U.S. organizations—notably education, business services, and technology firms—across Windows and Linux endpoints; actors exfiltrate data (using tools like rclone), encrypt files (appending .fog/.Fog/.FLOCKED), and publish stolen data on a TOR-based leak site, with attacks leveraging phishing, RDP/exploitation, credential dumping (Mimikatz), Cobalt Strike, and lateral movement; the report includes MITRE TTP mappings, a victim breakdown (~118 victims with 60 in the U.S.), recommended mitigations (MFA, EDR, segmentation, backups), and defensive services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.