Fog Ransomware Targets U.S. Organizations via Compromised VPN Credentials
Arctic Wolf Labs has identified a new ransomware variant, "Fog," impacting United States organizations, particularly within the education and recreation sectors. This ransomware operates through compromised VPN access.
Arctic Wolf Labs has identified a new ransomware variant, "Fog," impacting United States organizations, particularly within the education and recreation sectors. This ransomware operates through compromised VPN access.
The initial detection occurred on Thu, May 2, 2024, emphasizing vulnerabilities in remote access tools and rapid encryption tactics.
Arctic Wolf's Incident Response team examined several incidents beginning in early May 2024, focusing on U.S. organizations, with 80% from the education sector and 20% from the recreation sector.
Access was gained using compromised VPN credentials from two undisclosed vendors. The last recorded activity was on Thu, May 23, 2024.
Unlike traditional ransomware groups, Fog is classified as a "variant," distinguishing encryptor developers from operators, whose organizational structure remains undefined.
Intruders escalated privileges rapidly. In one instance, the pass-the-hash technique targeted administrative accounts for RDP access to Hyper-V and Veeam servers.
Credential stuffing facilitated lateral movement. PsExec was used for host spreading, with RDP and SMB for access. Windows Defender was disabled on servers, VMDK files in VM storage were encrypted, and Veeam object storage backups were deleted.
Ransom notes left on systems displayed identical text except for unique chat codes, linking to a .onion site. No data leak site was observed. Encrypted files were marked with the extensions .FOG or .FLOCKED.
The encryptor shares code blocks across samples, indicating a common source. It logs to DbgLog.sys in %AppData% and queries system information via NtQuerySystemInformation for thread allocation (2-16 processors).
The initial detection occurred on Thu, May 2, 2024, emphasizing vulnerabilities in remote access tools and rapid encryption tactics.
The JSON configuration specifies RSAPubKey, LockedExt, note name (readme.txt), and processes/services to terminate before encryption.
Discovery uses the Windows API, such as FindFirstVolume. Encryption employs deprecated CryptImportKey/CryptEncrypt API. Post-encryption, shadow copies are deleted using vssadmin delete shadows /all /quiet.
Tactic Technique Tools/Sub-techniques
Initial Access T1133 External Remote Services, T1078 Valid Accounts Compromised VPN credentials
Discovery T1046 Network Service Discovery, T1135 Network Share Discovery SoftPerfect Network Scanner, Advanced Port Scanner, SharpShares
Lateral Movement T1021 Remote Services (RDP/SMB), T1570 Lateral Tool Transfer PsExec
Credential Access T1003 OS Credential Dumping (NTDS), T1555 Password Stores, T1110 Brute Force Veeam-Get-Creds.ps1, credential stuffing
Defense Evasion T1562 Impair Defenses (Windows Defender), T1550 Pass the Hash
Impact T1486 Data Encrypted, T1490 Inhibit Recovery (vssadmin)
Type Indicator
SHA1 f7c8c60172f9ae4dab9f61c28ccae7084da90a06 (lck.exe)
SHA1 507b26054319ff31f275ba44ddc9d2b5037bd295 (locker_out.exe)
IP 5.230.33[.]176 (VPN login)
Filename readme.txt, DbgLog.sys, Veeam-Get-Creds.ps1
Extension .flocked, .fog
Based on reporting by GBHackers.
