Threat Advisory

New Fog Ransomware Targets US Education Sector via Breached VPNs

Threat: Ransomware
Targeted Region: United States
Targeted Sector: Education
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A new ransomware variant known as Fog has been observed targeting organizations in the United States, predominantly in the education and recreation sectors. It provides essential details about the Fog ransomware to help organizations defend against this emerging threat. The ransomware attacks have involved compromised VPN credentials, leading to unauthorized access and subsequent deployment of the ransomware.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A new ransomware variant known as Fog has been observed targeting organizations in the United States, predominantly in the education and recreation sectors. It provides essential details about the Fog ransomware to help organizations defend against this emerging threat. The ransomware attacks have involved compromised VPN credentials, leading to unauthorized access and subsequent deployment of the ransomware.[emaillocker id="1283"]

The Fog ransomware deploys several common techniques typically seen in other ransomware variants. It begins by creating a log file named DbgLog.sys in the %AppData% directory to track its status and error conditions. The ransomware leverages Windows internal APIs, such as NtQuerySystemInformation, to gather system information for allocating resources effectively. Key configurable options include an embedded public key for encryption, post-encryption file extensions, and processes to terminate before encryption begins. It utilizes deprecated Windows APIs for cryptographic operations and concludes by deleting volume shadow copies to hinder recovery efforts.

The Fog ransomware represents a significant threat due to its targeted approach and advanced techniques. Organizations should be vigilant in monitoring and securing VPN credentials, as well as implementing robust cybersecurity measures to detect and prevent such attacks. Regular updates to security protocols and maintaining comprehensive backups are crucial steps in mitigating the risk posed by this ransomware variant.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1078 Valid Accounts
T1133 External Remote Services
Execution T1059 Command and Scripting Interpreter
T1569 System Services
Persistence T1136 Create Account
Defense Evasion T1562 Impair Defenses
T1550 Use Alternate Authentication Material
T1078 Valid Accounts
T1140 Deobfuscate/Decode Files or Information
T1070 Indicator Removal
Credential Access T1003 OS Credential Dumping
T1555 Credentials from Password Stores
T1110 Brute Force
Discovery T1046 Network Service Discovery
T1135 Network Share Discovery
 Lateral Movement T1570 Lateral Tool Transfer
 T1021 Remote Services
Impact T1486 Data Encrypted for Impact
T1490  Inhibit System Recovery
T1489  Service Stop

REFERENCES:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/new-fog-ransomware-targets-us-education-sector-via-breached-vpns/

[/emaillocker]
crossmenu