Fog
Aliases: Fog ransomware
Source profile review date: 2026-06-01
Added to the source registry: 2024-07-16 · Source snapshot: 2026-09-15
Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.
Research status: Existing researched dossier
This dossier separates actor-specific source information from general defensive analysis. Recommendations and investigation questions are not additional claims about the actor. Public evidence remains limited where explicitly stated.
Locally generated translation; linguistic review is still pending.
Executive summary
Fog is a ransomware variant that Arctic Wolf saw in 2024 in U.S. education and recreation sectors, with later reporting around SonicWall SSL VPN- activity.
Fog is relevant due to rapid encryption, sector impact in education/recreation and observations around SSL VPN- access combined with Fog and Akira activity.
Latest five known victim claims
Loading stored claims…
These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.
Management summary
Fog is relevant because the group shows how VPN- access and fast ransomware deployment sectors such as education and recreation can hit. For visitors, this profile is meant to check their own environment before a claim or encryption becomes visible.
The key question is what step in the chain you can stop early: social engineering, vulnerable external access, valid accounts, lateral movement, data-processing, service disruption or misuse of management platforms.
This dossier therefore does not describe internal reporting requirements, but operational information: how the group works, which artifacts are known to the public, which victim patterns come back and what measures help directly.
Grouping and development
Arctic Wolf investigated Fog incidents against American organizations in education and recreation from May 2024. Later, Arctic Wolf described increased Fog and Akira activity linked to SonicWall SSL VPN.
Actor groups quickly change brand, affiliate or leak-site. Therefore, the profile is written around behavior and reliable source observations, not just around a name in the feed.
When a group is known mainly through leak-site claims, each claim must be linked to technical telemetry before conclusions are drawn.
Attack pattern from public cases
Fog incidents are about initial access, often via perimeter or VPN- risk, followed by rapid impact. The focus is on short response time and recovery preparation.
The attack usually takes place in phases: initial access, internal exploration, privilege use, data access, exfiltration and then encryption or publication pressure.
Note the link between identity and tooling. A single tool can be legitimate; the combination with suspicious login, new rights and data movement makes the incident.
Known IOCs and artifacts
Fog artifacts are case-dependent, but VPN-logins, fast file encryption, ransom notes and lateral movement around servers are important traces.
Use IOC pictorial features for retro-hunting, scope determination and confirmation. For structural detection, behavioral patterns are more important: remote access, data staging, service stops, RMM- abuse and abnormal outbound transfers.
Record by incident source, date, confidancy, host, account and command line. Old indicators without context can cause noise.
Victim pattern and lessons
Education and recreation show that sectors with many users, limited security capacity and operational pressure are attractive.
Victim patterns should be used as scenario scenarios: which sector, what dependency, what dates, what external access and what means of recovery were attractive?
A claim in the same sector is particularly useful as a checklist for one's own environment, not proof that the same actor is technically inside.
Practical detection logic
Detect suspicious SSL VPN-logins, new devices, impossible travel, followed by file-share access and encryption patterns.
Relationship is more important than loose alerts.VPN /SSO , endpoint, server logs, file access, cloud storage, firewall and backup platforms in one timeline.
Detect preliminary phases: discovery, archiving, Rclone or cloud sync usage, remote execution, service stops and access to backup or hypervisor management.
Concrete Hardening Priorities
Patch and monitor SonicWall/SSL VPN and other edge equipment, limit VPN- segments and test recovery for education and public service.
Force MFA to remote access, connect direct RDP where possible, limit management to jump hosts and monitor vendor accounts. Make data access visible on file shares and cloud environments.
Protect backups and virtualization with separate accounts, logging and network restrictions. Recoverability should remain out of reach of a compromised domain.
Identity, naming and attribution
For Fog, the operational starting point is an exact identity match. The local dossier records the following names or aliases: Fog ransomware. An alias is a search aid, not independent evidence of shared operators. Similar names, reused logos and the same extortion vocabulary cannot establish a relationship between groups. Analysts should retain the original spelling of a claim and distinguish the publisher, malware family and suspected intrusion operator. Those roles can belong to different people. This prevents an incident being assigned to the wrong group simply because a filename or public post resembles an earlier case. Any proposed relationship needs its own dated, attributable source.
Timeline and interpretation of dates
The source registry date available for Fog is 2024-07-16; the metadata snapshot was collected on 2026-09-15. These timestamps describe the available record, not a proven beginning of criminal operations. Registration may follow earlier activity, and a claim can concern an older incident. A defensible timeline separates suspected intrusion, data access, discovery by the victim, publication by the claimant and discovery by the monitoring service. The profile review date is another independent timestamp. Analysts should not silently convert one date into another. When sources disagree, preserve both observations and their provenance, then explain the uncertainty rather than presenting a falsely precise attack chronology.
Victim claims and targeting assessment
The victim panel for Fog shows up to five distinct organisations from the stored claim history. It is a moving observation window, not a complete incident census. Public listings can omit victims, repeat old material or exaggerate access. Consequently, a short run of organisations in one country or industry does not by itself prove deliberate targeting of that sector. The useful comparison is with the organisation's own dependencies: shared providers, remote access arrangements, exposed services and sensitive data flows. A supplier appearing in a claim justifies verification through established contacts, but does not establish that downstream customers were compromised. Separate confirmed statements from the claimant's assertions.
Indicators of compromise (IOCs)
Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.
| Type | Value | Source | Context |
|---|---|---|---|
| targeting | US education and recreation sectors | Arctic Wolf 2024 | Initial observed victimology. |
| access | SonicWall SSL VPN-linked activity | Arctic Wolf 2024 | Observed increase inFog /Akira intrusions linked to SonicWallSSL VPN . |
Sources
- Arctic Wolf: Lost in the Fog
- Arctic Wolf: Fog and Akira activity linked to SonicWall SSL VPN
- MITRE ATT&CK — Valid Accounts (defensive context)
- MITRE ATT&CK — External Remote Services (defensive context)
- MITRE ATT&CK — Exfiltration Over Web Service (defensive context)
- MITRE ATT&CK — Inhibit System Recovery (defensive context)
- Ransomware.live — Fog
Evidence and limitations
Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.