Ransomware Group:  
Fog



Sponsored by Hudson RockUse Hudson Rock's free cybercrime intelligence tools to learn how compromised credentials are impacting your business


Sites | External Information | Tools | Ransom Note(s) | Activity | Victims (18)

Fog, which uses the .flocked extension for encrypted files, was first observed in May in campaigns by Storm-0844, a threat actor known for distributing Akira. By June, Storm-0844 was deploying Fog more than Akira.


Sites

Title Available Last Visit FQDN Screenshot
FOG 🟢 2024-09-19 15:50:57.378782 xql562evsy7njcsngacphc2erzjfecwotdkobn3m4uxu2gtqh26newid.onion 📸
Blog 🟢 2024-09-19 15:51:13.067734 xbkv2qey6u3gd3qxcojynrt4h5sgrhkar6whuo74wo63hijnn677jnyd.onion 📸
Blog 🟢 2024-09-19 15:51:28.281713 xbkv2qey6u3gd3qxcojynrt4h5sgrhkar6whuo74wo63hijnn677jnyd.onion 📸

External information

Tools used

Discovery RMM Tools Defense Evasion Credential Theft OffSec Networking LOLBAS Exfiltration
Advanced Port Scanner Veeam-Get-Creds Metasploit PsExec
SharpShares
SoftPerfect NetScan

This information is provided by Ransomware-Tool-Matrix

Ransom Note(s)

Activity over time

18 Victims

US flag

Prentke Romich Company

Company logo


Discovery Date: 2024-09-18 16:03

Sector: Healthcare
250 GB

US flag

S. Walter Packaging

Company logo


Discovery Date: 2024-09-11 13:07

Sector: Manufacturing

DE flag

Clatronic International GmbH

Company logo


Discovery Date: 2024-09-11 13:05

Sector: Consumer Services
469 GB

US flag

Seaway Manufacturing Corp.

Company logo


Discovery Date: 2024-08-15 21:27

Sector: Manufacturing

 flag

IOI Corporation Berhad

Company logo


Discovery Date: 2024-08-06 16:23

Sector: Agriculture and Food Production
20 GB

 flag

Ziba Design

Company logo


Discovery Date: 2024-08-06 16:22

Sector: Business Services
22 GB

 flag

Hi-P International

Company logo


Discovery Date: 2024-08-05 17:36

Sector: Manufacturing
22 GB

NL flag

BASF - Nunhems

Company logo


Discovery Date: 2024-07-29 19:34

Sector: Agriculture and Food Production
30 GB

CA flag

City of Cold Lake

Company logo


Discovery Date: 2024-07-26 16:07

Sector: Public Sector
10 GB

US flag

Odessa College

Company logo


Discovery Date: 2024-07-25 17:41

Sector: Public Sector
18 GB

 flag

Wichita State University Campus of Applied Sciences and Technology

Company logo


Discovery Date: 2024-07-22 16:36

Sector: Education
10 GB

 flag

Geelong Lutheran College

Company logo


Discovery Date: 2024-07-16 22:05
Estimated Attack Date: 2024-06-19

Sector: Public Sector
4GB

 flag

Asbury Theological Seminary

Company logo


Discovery Date: 2024-07-16 22:04
Estimated Attack Date: 2024-06-24

Sector: Not Found
10 GB

 flag

Djg Projects

Company logo


Discovery Date: 2024-07-16 22:04
Estimated Attack Date: 2024-07-07

Sector: Construction
19.4GB

 flag

Verweij Elektrotechniek

Company logo


Discovery Date: 2024-07-16 22:03
Estimated Attack Date: 2024-07-04

Sector: Construction
95GB

US flag

Alvin Independent School District

Company logo


Discovery Date: 2024-07-16 21:43
Estimated Attack Date: 2024-07-04

Sector: Public Sector
60GB

US flag

West Allis-West Milwaukee School District

Company logo


Discovery Date: 2024-07-16 21:42
Estimated Attack Date: 2024-07-11

Sector: Public Sector
9,5 GB

OM flag

German University of Technology in Oman

Company logo


Discovery Date: 2024-07-16 21:42

Sector: Education
10 GB