EXECUTIVE SUMMARY
The Fog Ransomware group has expanded its attack vector beyond the education and recreational sectors, now focusing on more lucrative targets within the financial services sector. Evidence from a ransomware incident involving a mid-sized financial business indicates the involvement of Fog, which utilized compromised VPN credentials for initial access. It effectively contained the attack, isolating affected machines within minutes and thwarting any significant data encryption or theft.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
The Fog Ransomware group has expanded its attack vector beyond the education and recreational sectors, now focusing on more lucrative targets within the financial services sector. Evidence from a ransomware incident involving a mid-sized financial business indicates the involvement of Fog, which utilized compromised VPN credentials for initial access. It effectively contained the attack, isolating affected machines within minutes and thwarting any significant data encryption or theft.[emaillocker id="1283"]
Fog is identified as a variant of the STOP/DJVU ransomware family. It leverages compromised VPN credentials to infiltrate networks, employing techniques such as pass-the-hash attacks to escalate privileges. Once inside, it executes a series of destructive actions, including disabling protective measures, encrypting critical files especially Virtual Machine Disks and erasing backup data. The ransomware marks encrypted files with extensions like '.FOG' or '.FLOCKED' and leaves behind ransom notes directing victims to negotiation platforms on the Tor network. The attackers conduct network discovery through pings and reconnaissance tools, utilize compromised service accounts for lateral movement, and employ credential harvesting techniques to extract sensitive login data. They also deploy tools such as Rclone to sync and transfer data from compromised endpoints and use ‘locker.exe’ to facilitate file encryption, while executing commands to delete system shadow copies to hinder recovery efforts.
The emergence of Fog ransomware as a threat to the financial services sector underscores the evolving tactics. While the group has not been directly attributed to any established APT factions, its sophisticated techniques indicate the presence of highly skilled threat actors. Organizations in the financial sector should enhance their cybersecurity measures to safeguard against potential Fog ransomware attacks and remain vigilant against evolving threats targeting sensitive data and network integrity.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1190 | Exploit Public-Facing Application |
| Execution | T1059 | Command and Scripting Interpreter |
| T1106 | Native API | |
| Defense Evasion | T1078 | Valid Accounts |
| T1550 | Use Alternate Authentication Material | |
| T1027 | Obfuscated Files or Information | |
| Credential Access | T1555 | Credentials from Password Stores |
| Discovery | T1046 | Network Service Discovery |
| T1018 | Remote System Discovery | |
| Lateral Movement | T1021 | Remote Services |
| Collection | T1074 | Data Staged |
| Command and Control | T1071 | Application Layer Protocol |
| Exfiltration | T1048 | Exfiltration Over Alternative Protocol |
| Impact | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery |
REFERENCES:
The following reports contain further technical details:
https://cybersecuritynews.com/predator-spyware-infrastructure-returns/