Fog is a ransomware family observed since May 2024, initially prominent in attacks against education and recreation organizations in the United States. Subsequent deployments have affected organizations across multiple industries and regions, including financial services. Fog attacks combine rapid file encryption with data theft and threats to publish stolen information, although exfiltration was not observed in the earliest investigated incidents.
The Windows encryptor uses a JSON configuration to define encryption settings, exclusions, ransom-note content, and processes and services to terminate. It performs multithreaded encryption, targets files including virtual-machine disk images, and deletes volume shadow copies to impede recovery. Analyzed samples perform host and network reconnaissance. A documented multistage execution chain uses obfuscated code, anti-debugging and anti-sandbox checks, DLL unhooking, and reflective loading to evade analysis and security monitoring. Data exfiltration and persistence are generally implemented through separate attacker tools rather than built into the core encryptor.
Operators commonly obtain access through compromised VPN credentials, then use credential dumping, pass-the-hash, network scanning, RDP, SMB administrative shares, and PsExec to expand access. Attacks also target backup infrastructure; Fog deployments have been associated with exploitation of CVE-2024-40711 in Veeam Backup & Replication. Associated activity includes Storm-0844 and STAC 5881, both of which have also deployed Akira, a distinct ransomware family.
DOGE BIG BALLS is a customized Fog variant observed in a finance-themed archive delivery campaign. Its surrounding toolchain includes PowerShell-based persistence, credential theft, Active Directory propagation, remote-access tools, security-control bypasses, and exploitation of a vulnerable Intel driver through CVE-2015-2291. These capabilities belong to the broader infection chain and should not all be attributed to the Fog encryptor itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The author reports strong indications that Akira and Fog were exploiting CVE-2024-40766 for unauthorized access, with more than 100 suspected victim organizations as of December 23, 2024. However, the article explicitly states that exploitation had not been definitively established. At least 48,933 internet-exposed SonicWall devices reportedly remained unpatched as of December 24, 2024.
ktool.exe drops and loads the vulnerable driver (CVE-2015-2291) “iqvw64e.sys” as part of a Bring Your Own Vulnerable Driver (BYOVD) technique to gain kernel-level read/write access.
The vulnerability, CVE-2024-40711, was used as part of a threat activity cluster we named STAC 5881. Attacks leveraged compromised VPN appliances for access and used the VEEAM vulnerability to create a new local administrator account named “point”. Some cases in this cluster led to the deployment of Akira or Fog ransomware. | Some cases in this cluster led to the deployment of Akira or Fog ransomware. Fog emerged earlier this year, first seen in May.
CVE-2023-48365: Qlik Sense Enterprise HTTP Tunneling RCE (CVSS 9.9)
CVE-2024-21762: Fortinet FortiOS SSL VPN Out-of-Bounds Write RCE (CVSS 9.8)
CVE-2023-27997: Fortinet FortiOS SSL VPN Heap Buffer Overflow RCE - XORtigate (CVSS 9.8)
CVE-2025-23006: SonicWall SMA 1000 Pre-Auth Deserialization RCE (CVSS 9.8)
Referenced via: https://labs.watchtowr.com/by-executive-order-we-are-banning-blacklists-domain-level-rce-in-veeam-backup-replication-cve-2025-23120/ and multiple linked articles about Veeam RCE flaws.
Defenders should act now — ... patch CVE-2024-53704 (CVSS 9.8, CISA KEV) ... Exploitation Assessment ... CVE-2024-53704 ... Campaign Sessions 5 ... Confirm your SonicOS firmware is patched against CVE-2024-53704 (versions at or below 7.1.1-7058, 7.1.2-7019, or 8.0.0-8035 are vulnerable).
Fog ransomware accounts for another significant share, with some documented intrusions achieving full network encryption in under four hours.
Fog ransomware accounts for another significant share, with some documented intrusions achieving full network encryption in under four hours.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
public reporting will tie initial access in a consequential incident or bounded campaign to artifacts obtained through a separate, earlier edge-appliance exposure
atexec, Remote scheduled task, Scheduled Task events (4698)... In one engagement, attackers leveraged Active Directory Group Policy to distribute the ransomware payload as a scheduled task across domain-joined systems, ensuring simultaneous execution at scale.
public reporting will tie initial access in a consequential incident or bounded campaign to artifacts obtained through a separate, earlier edge-appliance exposure
Attacks leveraged compromised VPN appliances for access... Similar to the previous events, the threat actor used a compromised VPN appliance for access...
atexec, Remote scheduled task, Scheduled Task events (4698)... In one engagement, attackers leveraged Active Directory Group Policy to distribute the ransomware payload as a scheduled task across domain-joined systems, ensuring simultaneous execution at scale.
ktool.exe ... drops and loads the vulnerable driver (CVE-2015-2291) “iqvw64e.sys” as part of a Bring Your Own Vulnerable Driver (BYOVD) technique.
public reporting will tie initial access in a consequential incident or bounded campaign to artifacts obtained through a separate, earlier edge-appliance exposure
A qualifying case must clear four gates: Previously exposed artifacts are successfully reused. The reuse enables initial access in a consequential incident or bounded campaign.
PsExec and direct access to administrative shares (ADMIN$, C$, etc.) remained present in some engagements... The most common approach involved executing the ransomware binary from a single compromised system — typically a domain controller or infrastructure server — and encrypting data on remote systems through administrative shares (ADMIN$, C$).
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A separate ransomware-as-a-service family mentioned for comparison because it also favors VPN-based initial access. The article does not establish an operational relationship with Akira.
Ransomware associated with WMI, remote scheduled-task execution, RDP movement, and SMB staging.
Ransomware mentioned as leveraging a Veeam Backup & Replication (VBR) RCE vulnerability in attacks starting in October 2024.
Ransomware reported in intrusions leveraging SonicWall VPN access, with rapid progression to full network encryption in some cases.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.