Fog Ransomware — Ransomware Profile
Fog ransomware emerged mid-2024 targeting education, financial services, and recreation. Uses VPN compromise with LNK-based droppers deploying PowerShell scripts. Targets Windows and Linux. Named by Halcyon as top emerging group for 2025.Also tracked as
Fog
Tools & malware
- 7-Zip Collection
- Adaptix C2 Command and Control
- AnyDesk Remote Access
- cwiper.exe Loader
- Fog Encryptor Ransomware
- FreeFileSync Exfiltration
- GC2 Command and Control
- ktool.exe Privilege Escalation
- MegaSync Exfiltration
- PsExec Lateral Movement
- SMBExec Lateral Movement
- Stowaway Proxy
- Syteca (Ekran) Surveillance
Recent claimed victims
- Newtown Friends School (newtownfriends.org) 2025-03-20
- RAE (Real Academia Española) (rae.es) 2025-03-17
- El Camino Real Academy (elcaminorealacademy) 2025-03-13
- University Diagnostic Medical Imaging, PC (udmi.net) 2025-03-13
- Wilkinson Rogers (wilkinsonrogers.com) 2025-03-11
- Magnolia Manor (magnoliamanor.com) 2025-03-10
- FHNW 2025-03-06
- Kr3m 2025-03-06
- Flightsim studio 2025-03-06
- USGS 2025-03-06
- Blue Planet 2025-03-06
- Engikam 2025-03-06
- Eumetsat 2025-03-06
- 1X Internet 2025-03-06
- Inelmatic 2025-03-06
- Inet 2025-03-06
- WJCC Public Schools (wjccschools.org) 2025-03-06
- Bizcode 2025-03-06
- Oberlin Cable Co-op (oberlin.net) 2025-03-06
- Kotliva 2025-03-06
- Aeonsparx 2025-03-06
- Melexis 2025-03-06
- Euranova 2025-03-06
- CIE 2025-03-06
- InfoReach 2025-03-06
Vendor research
- Fog Ransomware 2025: Deep Dive into TTPs Picus Security
- Arctic Wolf Labs Observes Increased Fog and Akira Ransomware Activity Linked to SonicWall SSL VPN Arctic Wolf
- New Ransomware Fog Spread via Compromised VPNs Trend Micro
- Fog Ransomware: An Emerging Threat Arctic Wolf
- Fog Ransomware: A New Threat Targeting Education and Recreation SentinelOne