← All actors

Fog

Aliases: Fog ransomware

Source profile review date: 2026-06-01

Added to the source registry: 2024-07-16 · Source snapshot: 2026-09-15

Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.

Research status: Existing researched dossier

This dossier separates actor-specific source information from general defensive analysis. Recommendations and investigation questions are not additional claims about the actor. Public evidence remains limited where explicitly stated.

Locally generated translation; linguistic review is still pending.

Executive summary

Fog is a ransomware variant that Arctic Wolf saw in 2024 in U.S. education and recreation sectors, with later reporting around SonicWall SSL VPN- activity.

Fog is relevant due to rapid encryption, sector impact in education/recreation and observations around SSL VPN- access combined with Fog and Akira activity.

Latest five known victim claims

Loading stored claims…

    These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.

    Management summary

    Fog is relevant because the group shows how VPN- access and fast ransomware deployment sectors such as education and recreation can hit. For visitors, this profile is meant to check their own environment before a claim or encryption becomes visible.

    The key question is what step in the chain you can stop early: social engineering, vulnerable external access, valid accounts, lateral movement, data-processing, service disruption or misuse of management platforms.

    This dossier therefore does not describe internal reporting requirements, but operational information: how the group works, which artifacts are known to the public, which victim patterns come back and what measures help directly.

    Grouping and development

    Arctic Wolf investigated Fog incidents against American organizations in education and recreation from May 2024. Later, Arctic Wolf described increased Fog and Akira activity linked to SonicWall SSL VPN.

    Actor groups quickly change brand, affiliate or leak-site. Therefore, the profile is written around behavior and reliable source observations, not just around a name in the feed.

    When a group is known mainly through leak-site claims, each claim must be linked to technical telemetry before conclusions are drawn.

    Attack pattern from public cases

    Fog incidents are about initial access, often via perimeter or VPN- risk, followed by rapid impact. The focus is on short response time and recovery preparation.

    The attack usually takes place in phases: initial access, internal exploration, privilege use, data access, exfiltration and then encryption or publication pressure.

    Note the link between identity and tooling. A single tool can be legitimate; the combination with suspicious login, new rights and data movement makes the incident.

    Known IOCs and artifacts

    Fog artifacts are case-dependent, but VPN-logins, fast file encryption, ransom notes and lateral movement around servers are important traces.

    Use IOC pictorial features for retro-hunting, scope determination and confirmation. For structural detection, behavioral patterns are more important: remote access, data staging, service stops, RMM- abuse and abnormal outbound transfers.

    Record by incident source, date, confidancy, host, account and command line. Old indicators without context can cause noise.

    Victim pattern and lessons

    Education and recreation show that sectors with many users, limited security capacity and operational pressure are attractive.

    Victim patterns should be used as scenario scenarios: which sector, what dependency, what dates, what external access and what means of recovery were attractive?

    A claim in the same sector is particularly useful as a checklist for one's own environment, not proof that the same actor is technically inside.

    Practical detection logic

    Detect suspicious SSL VPN-logins, new devices, impossible travel, followed by file-share access and encryption patterns.

    Relationship is more important than loose alerts.VPN /SSO , endpoint, server logs, file access, cloud storage, firewall and backup platforms in one timeline.

    Detect preliminary phases: discovery, archiving, Rclone or cloud sync usage, remote execution, service stops and access to backup or hypervisor management.

    Concrete Hardening Priorities

    Patch and monitor SonicWall/SSL VPN and other edge equipment, limit VPN- segments and test recovery for education and public service.

    Force MFA to remote access, connect direct RDP where possible, limit management to jump hosts and monitor vendor accounts. Make data access visible on file shares and cloud environments.

    Protect backups and virtualization with separate accounts, logging and network restrictions. Recoverability should remain out of reach of a compromised domain.

    Identity, naming and attribution

    For Fog, the operational starting point is an exact identity match. The local dossier records the following names or aliases: Fog ransomware. An alias is a search aid, not independent evidence of shared operators. Similar names, reused logos and the same extortion vocabulary cannot establish a relationship between groups. Analysts should retain the original spelling of a claim and distinguish the publisher, malware family and suspected intrusion operator. Those roles can belong to different people. This prevents an incident being assigned to the wrong group simply because a filename or public post resembles an earlier case. Any proposed relationship needs its own dated, attributable source.

    Timeline and interpretation of dates

    The source registry date available for Fog is 2024-07-16; the metadata snapshot was collected on 2026-09-15. These timestamps describe the available record, not a proven beginning of criminal operations. Registration may follow earlier activity, and a claim can concern an older incident. A defensible timeline separates suspected intrusion, data access, discovery by the victim, publication by the claimant and discovery by the monitoring service. The profile review date is another independent timestamp. Analysts should not silently convert one date into another. When sources disagree, preserve both observations and their provenance, then explain the uncertainty rather than presenting a falsely precise attack chronology.

    Victim claims and targeting assessment

    The victim panel for Fog shows up to five distinct organisations from the stored claim history. It is a moving observation window, not a complete incident census. Public listings can omit victims, repeat old material or exaggerate access. Consequently, a short run of organisations in one country or industry does not by itself prove deliberate targeting of that sector. The useful comparison is with the organisation's own dependencies: shared providers, remote access arrangements, exposed services and sensitive data flows. A supplier appearing in a claim justifies verification through established contacts, but does not establish that downstream customers were compromised. Separate confirmed statements from the claimant's assertions.

    Indicators of compromise (IOCs)

    Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.

    TypeValueSourceContext
    targetingUS education and recreation sectorsArctic Wolf 2024Initial observed victimology.
    accessSonicWall SSL VPN-linked activityArctic Wolf 2024Observed increase inFog /Akira intrusions linked to SonicWallSSL VPN .

    Sources

    Evidence and limitations

    Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.