Fog, a ransomware variant belonging to the STOP/DJVU that previously targeted education and entertainment sectors, has turned its attention to profitable targets in the financial industry.
See also: 2024: Significant increase in active ransomware gangs

In early August 2024, hackers used VPN credentials to launch a ransomware attack against a mid-sized financial institution. The criminals used the Fog ransomware (also known as “ Lost in the Fog ”) to target sensitive data on Windows and Linux operating system endpoints .
However, Adlumin 's cutting-edge technology – which uses bait files as sensors to detect ransomware activity within the network – was able to thwart the attack .
Fog ransomware was first detected in 2021.It primarily targets industries such as education and entertainment and breaches network defenses by exploiting vulnerabilities in compromised VPN.
See also: Lockbit gang claims responsibility for TDSB ransomware attack
Once inside a network, Fog significantly increases its influence by using sophisticated methods, such as pass-the-hash, to escalate privileges.
Furthermore, the Fog ransomware proceeds to take several measures aimed at disrupting network security. These consist of disabling security features, encrypting important files, especially Virtual Machine Disks (VMDKs), and deleting backups, leaving victims with little choice but to consider paying the ransom.

The encrypted files, usually identified by extensions such as “ .FOG ” or “ .FLOCKED ,” are accompanied by a ransom message that directs victims to a Tor network trading platform
The Adlumin team determined that the attack originated from a Russian IP address and traced the hack to an unprotected device. Using domain trust information, the Fog ransomware attackers were able to move laterally through the network using two compromised service accounts.
The next stage involved backing up login information stored on endpoints for multiple users, including encrypted Google Chrome credentials, using Microsoft’s command-line utility “esentutl.exe.” The hackers synced and transferred data from infected endpoints using “Rclone,” an efficient open-source command-line tool.
The tool used to spread the ransomware was identified as “locker.exe,” indicating that it played a role in “locking” or encrypting data. The ransom message was then posted in a file called “readme.txt” on each compromised endpoint. To prevent victims from being able to restore their files from backups, the attackers also deleted system shadow copies using PowerShell and WMIC.
See also: Ransomware gangs hit Southeast Asia
Ransomware attacks, such as Fog, have emerged as a widespread threat in the digital landscape, targeting individuals and organizations. These malicious attacks involve encrypting the victim’s data, with the attacker demanding a ransom payment in exchange for the decryption key. The consequences of such attacks can be devastating, leading to significant financial losses, operational disruptions, and loss of sensitive information. As cybercriminal tactics evolve, it is becoming increasingly important for individuals and businesses to implement strong security measures, such as regular data backups, employee training , and up-to-date antivirus software, to mitigate the risks associated with ransomware.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: cybersecuritynews
