logo

Fog Ransomware Attack Chain Leverages Legitimate and Open-Source Tools

ID: 88d2c922-b286-5551-b7c6-82ca0ff0363d

STIX ID: report--88d2c922-b286-5551-b7c6-82ca0ff0363d

Feed Name: Halcyon Blog

Threat Score
80/100

Date Published: 2025-06-12

Date Updated: 2026-04-28

...
...

Researchers observed a Fog ransomware attack against a financial institution in Asia in which operators blended uncommon legitimate and open-source tools (notably Syteca, GC2, and Stowaway) alongside common utilities (PsExec, Impacket, 7-Zip, MegaSync) to steal credentials, move laterally, maintain persistence, stage exfiltration, and deploy ransomware; Fog is a STOP/DJVU variant that disables defenses, deletes backups, uses AES-256 with RSA-2048 for keys, and has adopted double-extortion tactics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.