Fog is a financially motivated ransomware-as-a-service operation active since 2024. It conducts double extortion, combining file encryption with threats to publish stolen information through a dedicated leak site. Its targets include organizations in technology, education, manufacturing, transportation, healthcare, and energy, with documented targeting of Turkey's energy sector. Its operators' country of origin is not established. Fog intrusions have involved compromised SonicWall SSL VPN accounts and exploitation of CVE-2024-40711 in Veeam Backup & Replication. Operators target Veeam's credential database to obtain credentials for domain accounts, cloud services, and backup repositories. Observed lateral-movement techniques include native Windows Management Instrumentation remote process execution, Task Scheduler, RDP, and SMB administrative-share staging. Some documented intrusions have progressed from VPN access to network encryption in under four hours. Analyzed Fog ransomware deployments use multistage loaders with junk code, anti-sandbox and anti-debugging checks, API hashing, reflective DLL loading, and DLL unhooking to evade analysis and security monitoring. The ransomware gathers host and network information, enumerates processes and services, attempts to terminate configured targets, deletes volume shadow copies, and encrypts files using multiple threads. Fog is distinct from Akira despite overlapping VPN-focused tradecraft. Shared cryptocurrency-laundering infrastructure has linked Fog, Akira, and Frag financially, but does not establish that they are the same operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A separate ransomware-as-a-service operation mentioned for comparison with Akira because both favor VPN-based initial access. No shared operators or organizational relationship are established.
Referenced as part of prior intrusions involving SonicWall SSL VPN accounts; the content does not establish provenance of the credentials or focus primarily on Fog itself.
Conducting ransomware intrusions via exploitation of SonicWall SSLVPN access weaknesses, particularly CVE-2024-40766, alongside credential-based access and fast post-compromise activity.
Associated with exploitation of Veeam Backup & Replication vulnerabilities in ransomware operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.