Fog is a financially motivated ransomware operation first observed in 2024 and active across Windows and virtualized environments, including attacks affecting ESXi and backup infrastructure. The group has been associated with rapid, opportunistic intrusions that frequently rely on valid or compromised VPN credentials for initial access, particularly through SonicWall SSL VPN accounts, and has also been linked to exploitation of vulnerabilities in SonicWall SonicOS and Veeam Backup & Replication. Reporting indicates Fog heavily targeted U.S. higher education early in its activity and has also been observed targeting the energy sector in Turkey, alongside victims in technology, manufacturing, transportation, and education. Fog conducts double extortion, combining file encryption with data theft and leak-site pressure. Operators maintain a data leak site and victim negotiation portal and have claimed responsibility for encrypting victim data while exfiltrating a portion for coercion. Intrusions have shown very short dwell times, with full encryption sometimes occurring within hours of initial access. Post-compromise activity includes reconnaissance, credential theft, privilege escalation, lateral movement, service and process termination, deletion of shadow copies and backups, and multithreaded encryption. Observed tradecraft includes abuse of valid accounts, pass-the-hash, brute forcing of user accounts, browser and directory credential extraction, use of RDP for persistence, and deployment of common offensive tooling such as PsExec, Metasploit, Mimikatz, secretsdump, network scanners, and exfiltration utilities. Malware analysis of Fog samples shows layered defensive evasion and anti-analysis measures, including anti-sandbox checks, anti-debugging, API hashing, reflective loading, and DLL unhooking to remove security product hooks. The ransomware decrypts embedded configuration data, performs host and network reconnaissance, attempts to stop selected services and processes, and then encrypts files while excluding configured paths and targets. Fog has been described as a newer operation whose operators or affiliates appear experienced, with some assessments suggesting it may have attracted personnel from BlackCat and LockBit ecosystems. Blockchain and laundering analysis has also linked Fog operationally with Akira and Frag through shared laundering infrastructure, though this does not by itself establish common ownership.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as part of prior intrusions involving SonicWall SSL VPN accounts; the content does not establish provenance of the credentials or focus primarily on Fog itself.
Conducting ransomware intrusions via exploitation of SonicWall SSLVPN access weaknesses, particularly CVE-2024-40766, alongside credential-based access and fast post-compromise activity.
Associated with exploitation of Veeam Backup & Replication vulnerabilities in ransomware operations.
Named as one of several ransomware operations weaponizing a critical Veeam Backup & Replication RCE flaw in attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.