Threat Advisory

Fog Ransomware Targeting Financial Services by Compromising VPNs for Attacks

Threat: Ransomware
Targeted Region: Global
Targeted Sector: Finance & Banking, Education, Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

The Fog Ransomware group has expanded its attack vector beyond the education and recreational sectors, now focusing on more lucrative targets within the financial services sector. Evidence from a ransomware incident involving a mid-sized financial business indicates the involvement of Fog, which utilized compromised VPN credentials for initial access. It effectively contained the attack, isolating affected machines within minutes and thwarting any significant data encryption or theft.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

The Fog Ransomware group has expanded its attack vector beyond the education and recreational sectors, now focusing on more lucrative targets within the financial services sector. Evidence from a ransomware incident involving a mid-sized financial business indicates the involvement of Fog, which utilized compromised VPN credentials for initial access. It effectively contained the attack, isolating affected machines within minutes and thwarting any significant data encryption or theft.[emaillocker id="1283"]

 

Fog is identified as a variant of the STOP/DJVU ransomware family. It leverages compromised VPN credentials to infiltrate networks, employing techniques such as pass-the-hash attacks to escalate privileges. Once inside, it executes a series of destructive actions, including disabling protective measures, encrypting critical files especially Virtual Machine Disks and erasing backup data. The ransomware marks encrypted files with extensions like '.FOG' or '.FLOCKED' and leaves behind ransom notes directing victims to negotiation platforms on the Tor network. The attackers conduct network discovery through pings and reconnaissance tools, utilize compromised service accounts for lateral movement, and employ credential harvesting techniques to extract sensitive login data. They also deploy tools such as Rclone to sync and transfer data from compromised endpoints and use ‘locker.exe’ to facilitate file encryption, while executing commands to delete system shadow copies to hinder recovery efforts.

 

The emergence of Fog ransomware as a threat to the financial services sector underscores the evolving tactics. While the group has not been directly attributed to any established APT factions, its sophisticated techniques indicate the presence of highly skilled threat actors. Organizations in the financial sector should enhance their cybersecurity measures to safeguard against potential Fog ransomware attacks and remain vigilant against evolving threats targeting sensitive data and network integrity.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access  T1190 Exploit Public-Facing Application
Execution T1059 Command and Scripting Interpreter
T1106 Native API
Defense Evasion T1078 Valid Accounts
 T1550 Use Alternate Authentication Material
T1027 Obfuscated Files or Information
 Credential Access T1555 Credentials from Password Stores
Discovery  T1046 Network Service Discovery
T1018 Remote System Discovery
Lateral Movement  T1021 Remote Services
Collection T1074 Data Staged
Command and Control T1071 Application Layer Protocol
 Exfiltration T1048 Exfiltration Over Alternative Protocol
Impact T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery

REFERENCES:

The following reports contain further technical details:
https://cybersecuritynews.com/predator-spyware-infrastructure-returns/

[/emaillocker]
crossmenu