Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Fog Ransomware

180
Global rank
160 infographic chevron month
Month rank
126 infographic chevron week
Week rank
0
IOCs

Fog is a ransomware strain that locks and steals sensitive information both on Windows and Linux endpoints. The medial ransom demand is $220,000. The medial payment is $100,000. First spotted in the spring of 2024, it was used to attack educational organizations in the USA, later expanding on other sectors and countries. Main distribution method — compromised VPN credentials.

Ransomware
Type
Unknown
Origin
1 April, 2024
First seen
9 September, 2026
Last seen

How to analyze Fog Ransomware with ANY.RUN

Type
Unknown
Origin
1 April, 2024
First seen
9 September, 2026
Last seen

IOCs

IP addresses
3.5.217.108
40.126.32.136
150.171.27.11
2.16.204.135
52.123.243.220
150.171.28.11
23.48.23.146
172.211.123.248
48.209.133.15
23.12.138.206
104.18.23.222
48.209.138.168
150.171.109.193
150.171.109.99
57.153.246.3
74.179.77.204
23.12.141.172
74.179.77.164
2.20.245.174
23.12.131.34
Hashes
450a9842e11ffb8e1267dd88d15699c0614387e2e6c6f88c45b8f69fbed4c961
d20361df07912a39ea2ea487efdb0f5c1d47a008dc1e39d242d18b95a5ee0886
7110b29b4c64bb33364c35b9eedbd643b16f2d4f6f108deb5cdcfd7c8becc527
2ba6745f702bba40d269a33485ef52885992a498765c068ff4ea1d8db4db56b4
5ad16db790eafd557049f50fecfb8a9ac5a7f4463b82044f86c9fafe22cb7950
2080842a3ce27df715d170ec230896541cc9d26cb7d11b258ba385456b7f70e6
327584205b9cce3a275799b0b8fdccaf62a6d173c841eaca9c47304c3c1116c5
4a26a6d62e43d77db8d5d0b8e795827f16875e3edfe83e639699bb8565a24d37
347bad701d74abd9ff1cfb998c141a8554e369f38f66010bebc4b613bbf346c3
d5cec77d87bf8ed02a4285e4c708884c850af92eabef552891698904893830fd
eb2b2b96cb8b07f678eb2458e9006257fcaaa48c41f77359e327729fed711406
cd0dd26304b88c20801fe80b33c49c009e2e5d4411b5d7f83252e1d90cd461c6
81ff65efc4487853bdb4625559e69ab44f19e0f5efbd6d5b2af5e3ab267c8e06
a55f1fc6ba1694e4e0d3c9b6a76b8a6fffcfe24311991b1ce88fc5189d45e4f5
1bda750084f20306722008016420e1912ba608ca8efb9c661f7e7efcf5e89673
e22d34bbd915eeb277d4f4138d176eace5577cf035ef7c2c80a4bc4d9b6c0e1d
8013ac030684b86d754bbfbab8a9cec20caa4dd9c03022715ff353dc10e14031
4355d9a8a115ba4e41178b456a8a5578846eb1f7ec9509249c2405f758f31731
73002d28d89721be4401474eee3e28cdf10aa006cfef5750ba4c3d920d198943
84acd485899333cbdf5ad1f68d8c31658d5ecc9ee8dddf62098a2218687d7e77
Domains
settings-win.data.microsoft.com
p13n.adobe.io
edge.microsoft.com
slscr.update.microsoft.com
www.bing.com
copilot.microsoft.com
www.microsoft.com
go.microsoft.com
edge-consumer-static.azureedge.net
update.googleapis.com
config.edge.skype.com
login.live.com
fe3cr.delivery.mp.microsoft.com
api.edgeoffer.microsoft.com
crl.microsoft.com
ocsp.digicert.com
amazonaws.com
email-attack-attachments.s3.eu-north-1.amazonaws.com
armmf.adobe.com
client.wns.windows.com
URLs
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:mhbckgltdpetnmbwgax01_0oawnadtpy7hbk3inuam4&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://email-attack-attachments.s3.eu-north-1.amazonaws.com/30a6688899c22a3ce4c1b977fae762e3f7342d776e1aa2c90835e785d42f60c1?x-amz-algorithm=aws4-hmac-sha256&x-amz-checksum-mode=enabled&x-amz-credential=akiaxwma6xbr3pntgmfa%2f20260909%2feu-north-1%2fs3%2faws4_request&x-amz-date=20260909t102427z&x-amz-expires=900&x-amz-signedheaders=host&x-id=getobject&x-amz-signature=40ad95da9941de39511392bb6ca9f86260ead7230cc6ffd7a2d3484c0407cc36
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d264%2526e%253d1
https://update.googleapis.com/service/update2/json?cup2key=14:adm1tthzeug-s0c-nmyxelquqj8cdacvqbovbu3wwag&cup2hreq=86dd1b27331bba858173296a0ee48aa82c2426b3fdf783a7a61cf610cba1d7dd
https://www.bing.com/api/shopping/v1/user/shoppingsettings?enabledservicefeaturesv2=edgeserverux.shopping.cashbackeumarkets,edgeserverux.shopping.msedgeshoppingcashbackdismisstimeout2s
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
Last Seen at

Recent blog posts

post image
6 Months on Alert: Get H1 2026 Cyber Risk Rep...
watchers 303
comments 0
post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 5151
comments 0
post image
15 Minutes Saved Per Alert: How a Lean German...
watchers 10231
comments 0

What is Fog malware?

Fog is a ransomware that was first noticed in April 2024 actively using compromised virtual private network (VPN) credentials to gain access to organization networks. It started with attacking educational and recreational sectors, later expanding on financial and manufacturing industries.

Fog turned out to be capable of encrypting files with alarming speed: the shortest time observed was 2 hours after appearing in the network. It encrypts data on the device and any mounted shares adding extensions such as .fog, .ffog, .flocked to the affected files.

Fog Ransomware note in the ANY.RUN Sandbox Fog analysis session the ANY.RUN sandbox and its ransom note

After infiltrating a network, Fog explores it to understand its topology and identify critical assets. Further it escalates privileges and moves laterally across the network to establish a strong foothold into it. Before encryption, valuable data gets exfiltrated to be used for double extortion tactics.

The malware generates a .txt note demanding a ransom for decrypting files and avoiding the publication of sensitive data.

Fog counters recovery efforts, deletes system volume shadow copies, and avoids detection both by security software and by users observing disruptions in the system’s functioning.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Technical details of Fog malware

Fog is equipped with extensive capabilities:

  • For infiltration, uses compromised VPN credentials.
  • For Linux-based endpoints, weak SSH passwords or misconfigured network services are also exploited.
  • Once in the network, performs "pass-the-hash" attacks on administrator accounts, which are used to establish RDP connections to Windows servers running Hyper-V.
  • Disables Windows Defender to prevent alerting the victim before the execution of the encrypter.
  • Calls Windows API to gather information about the network, such as the number of available logical processors to allocate threads for a multi-threaded encryption routine.
  • Exploits Linux privilege escalation vulnerabilities (e.g., Dirty Pipe or Sudo-related flaws), misconfigured sudo privileges, or local exploits.
  • Establishes persistence by adding malicious system tasks, modifying startup scripts, or planting backdoors in binaries.
  • Terminates security services and processes from a list encoded in its config.
  • Attackers use legitimate remote access tools like AnyDesk to establish command-and-control (C2) communication.
  • A ransom note is copied to the affected directories. It contains a link to a Tor website with a chat interface for negotiations.

The Execution process of Fog

To see how Fog infects a system, we can upload its sample to ANY.RUN's Interactive Sandbox, which provides a safe virtual environment for detonating and analyzing malware and phishing threats.

Fog Ransomware MITRE in the ANY.RUN Sandbox TTP matrix of a Fog attack via Interactive Sandbox

Fog ransomware operates via a sophisticated execution chain that begins with the initial compromise of a target system. Attackers gain access by exploiting known vulnerabilities or purchasing compromised credentials from Initial Access Brokers.

Fog Ransomware process in the ANY.RUN Sandbox Fog’s malicious process that encrypts data and deletes copies viewed in ANY.RUN’s sandbox

Once inside the network, they conduct reconnaissance, scanning for valuable data and identifying potential encryption targets. This phase is crucial because it allows the attackers to map out the network and establish lateral movement paths to propagate the ransomware effectively.

Once executed, the malware begins encrypting files on both the local system and any mounted shares, appending extensions such as .fog, .ffog, or .flocked, making it evident the files have been compromised.

Additionally, it maintains a whitelist of files and directories to avoid rendering the system unusable, which could alert victims to its presence before it completes encryption. This careful planning allows the attackers to maximize damage while minimizing detection.

As part of its protocol, Fog generates a ransom note named readme.txt, which is distributed across affected systems. This note typically includes an introduction to the Fog group, details about the encryption process, and instructions on how victims can contact the attackers and arrange payment.

The speed at which Fog ransomware can execute its entire chain — from initial access to file encryption — is alarmingly rapid; some reports indicate that the process can occur in as little as two hours.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Collect Threat Intelligence on Fog Ransomware

Gather Fog’s artifacts, IOCs, and TTPs to arm your defenses with fresh data backed by a community of security experts. You can get a list of sandbox reports featuring the most recent analyses of Fog samples.

TI Lookup from ANY.RUN supports over 40 search parameters, including IPs, domains, and file names.

Fog Ransomware search results the ANY.RUN's TI Lookup Fog analysis sessions listed by ANY.RUN’s Threat Intelligence Lookup

Use the threat name or related data like hash values or network connections as search queries to understand the malware's behavior.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Distribution methods of Fog

For infiltration, it uses compromised VPN credentials leaked from at least two different VPN gateway vendors and bought on the dark market, weak SSH passwords, or misconfigured network services. Brute force attacks against remote desktop protocol (RDP) are also employed.

Use threat intelligence services like TI Lookup by ANY.RUN to gather relevant IOCs for setting up early detection and alerts in your security infrastructure.

Conclusion

Fog is a dangerous and sophisticated ransomware that promises companies operational disruption, financial losses and long-term damages to their business.

It accesses corporate networks by exploiting compromised VPN credentials. Fog strikes rapidly, and preventive measures must be taken to avoid an attack. Keep your security systems up to date and fine-tuned against topical attacks, use tools like ANY.RUN’s TI Lookup and Sandbox to gather threat intelligence and enforce your protection.

Sign up for a free ANY.RUN account to strengthen your security posture!

HAVE A LOOK AT

Loader screenshot
Loader
loader downloader
A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.
Read More
WhiteSnake screenshot
WhiteSnake
whitesnake
WhiteSnake is a stealer with advanced remote access capabilities. The attackers using this malicious software can control infected computers and carry out different malicious activities, including stealing sensitive files and data, recording audio, and logging keystrokes. WhiteSnake is sold on underground forums and often spreads through phishing emails.
Read More
LokiBot screenshot
LokiBot
lokibot loader trojan
LokiBot was developed in 2015 to steal information from a variety of applications. Despite the age, this malware is still rather popular among cybercriminals.
Read More
MassLogger screenshot
MassLogger
masslogger
MassLogger is a credential stealer and keylogger first identified in April 2020. It has been actively used in cyber campaigns to exfiltrate sensitive information from compromised systems. It is designed for easy use by less tech-savvy actors and is prominent for the capability of spreading via USB drives. It targets both individuals and organizations in various industries, mostly in Europe and the USA.
Read More
Cactus Ransomware screenshot
Cactus ransomware-as-a-service (RaaS) was first caught in March 2023 targeting corporate networks. It became known for its self-encrypting payload and double extortion tactics. Cactus primarily targets large enterprises across industries in finance, manufacturing, IT, and healthcare. It is known for using custom encryption techniques, remote access tools, and penetration testing frameworks to maximize damage.
Read More
DragonForce screenshot
DragonForce
dragonforce
DragonForce is a ransomware strain operating under the Ransomware-as-a-Service (RaaS) model. First reported in December 2023, it encrypts files with ChaCha8, renames them with random strings, and appends “.dragonforce_encrypted.” By disabling backups, wiping recovery, and spreading across SMB shares, DragonForce maximizes damage and pressures victims into multimillion-dollar ransom negotiations. It has targeted manufacturing, construction, IT, healthcare, and retail sectors worldwide, making it a severe threat to modern enterprises.
Read More