Fog Ransomware Attack Chain Leverages Legitimate and Open-Source Tools
ID: 88d2c922-b286-5551-b7c6-82ca0ff0363d
STIX ID: report--88d2c922-b286-5551-b7c6-82ca0ff0363d
Feed Name: Halcyon Blog
Researchers observed a Fog ransomware attack against a financial institution in Asia in which operators blended uncommon legitimate and open-source tools (notably Syteca, GC2, and Stowaway) alongside common utilities (PsExec, Impacket, 7-Zip, MegaSync) to steal credentials, move laterally, maintain persistence, stage exfiltration, and deploy ransomware; Fog is a STOP/DJVU variant that disables defenses, deletes backups, uses AES-256 with RSA-2048 for keys, and has adopted double-extortion tactics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
