Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Fog Ransomware Targets U.S. Organizations via Compromised VPN Credentials

Arctic Wolf Labs has identified a new ransomware variant, "Fog," impacting United States organizations, particularly within the education and recreation sectors. This ransomware operates through compromised VPN access.

Arctic Wolf Labs has identified a new ransomware variant, "Fog," impacting United States organizations, particularly within the education and recreation sectors. This ransomware operates through compromised VPN access.

The initial detection occurred on Thu, May 2, 2024, emphasizing vulnerabilities in remote access tools and rapid encryption tactics.

Arctic Wolf's Incident Response team examined several incidents beginning in early May 2024, focusing on U.S. organizations, with 80% from the education sector and 20% from the recreation sector.

Access was gained using compromised VPN credentials from two undisclosed vendors. The last recorded activity was on Thu, May 23, 2024.

Unlike traditional ransomware groups, Fog is classified as a "variant," distinguishing encryptor developers from operators, whose organizational structure remains undefined.

Intruders escalated privileges rapidly. In one instance, the pass-the-hash technique targeted administrative accounts for RDP access to Hyper-V and Veeam servers.

Credential stuffing facilitated lateral movement. PsExec was used for host spreading, with RDP and SMB for access. Windows Defender was disabled on servers, VMDK files in VM storage were encrypted, and Veeam object storage backups were deleted.

Ransom notes left on systems displayed identical text except for unique chat codes, linking to a .onion site. No data leak site was observed. Encrypted files were marked with the extensions .FOG or .FLOCKED.

The encryptor shares code blocks across samples, indicating a common source. It logs to DbgLog.sys in %AppData% and queries system information via NtQuerySystemInformation for thread allocation (2-16 processors).

The initial detection occurred on Thu, May 2, 2024, emphasizing vulnerabilities in remote access tools and rapid encryption tactics.
Noah Redmond · Thehackingpost

The JSON configuration specifies RSAPubKey, LockedExt, note name (readme.txt), and processes/services to terminate before encryption.

Discovery uses the Windows API, such as FindFirstVolume. Encryption employs deprecated CryptImportKey/CryptEncrypt API. Post-encryption, shadow copies are deleted using vssadmin delete shadows /all /quiet.

Tactic Technique Tools/Sub-techniques

Initial Access T1133 External Remote Services, T1078 Valid Accounts Compromised VPN credentials

Discovery T1046 Network Service Discovery, T1135 Network Share Discovery SoftPerfect Network Scanner, Advanced Port Scanner, SharpShares

Lateral Movement T1021 Remote Services (RDP/SMB), T1570 Lateral Tool Transfer PsExec

Credential Access T1003 OS Credential Dumping (NTDS), T1555 Password Stores, T1110 Brute Force Veeam-Get-Creds.ps1, credential stuffing

Defense Evasion T1562 Impair Defenses (Windows Defender), T1550 Pass the Hash

Advertisement

Impact T1486 Data Encrypted, T1490 Inhibit Recovery (vssadmin)

Type Indicator

SHA1 f7c8c60172f9ae4dab9f61c28ccae7084da90a06 (lck.exe)

SHA1 507b26054319ff31f275ba44ddc9d2b5037bd295 (locker_out.exe)

IP 5.230.33[.]176 (VPN login)

Filename readme.txt, DbgLog.sys, Veeam-Get-Creds.ps1

Extension .flocked, .fog

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories