EXECUTIVE SUMMARY
A new ransomware variant known as Fog has been observed targeting organizations in the United States, predominantly in the education and recreation sectors. It provides essential details about the Fog ransomware to help organizations defend against this emerging threat. The ransomware attacks have involved compromised VPN credentials, leading to unauthorized access and subsequent deployment of the ransomware.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A new ransomware variant known as Fog has been observed targeting organizations in the United States, predominantly in the education and recreation sectors. It provides essential details about the Fog ransomware to help organizations defend against this emerging threat. The ransomware attacks have involved compromised VPN credentials, leading to unauthorized access and subsequent deployment of the ransomware.[emaillocker id="1283"]
The Fog ransomware deploys several common techniques typically seen in other ransomware variants. It begins by creating a log file named DbgLog.sys in the %AppData% directory to track its status and error conditions. The ransomware leverages Windows internal APIs, such as NtQuerySystemInformation, to gather system information for allocating resources effectively. Key configurable options include an embedded public key for encryption, post-encryption file extensions, and processes to terminate before encryption begins. It utilizes deprecated Windows APIs for cryptographic operations and concludes by deleting volume shadow copies to hinder recovery efforts.
The Fog ransomware represents a significant threat due to its targeted approach and advanced techniques. Organizations should be vigilant in monitoring and securing VPN credentials, as well as implementing robust cybersecurity measures to detect and prevent such attacks. Regular updates to security protocols and maintaining comprehensive backups are crucial steps in mitigating the risk posed by this ransomware variant.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1078 | Valid Accounts |
| T1133 | External Remote Services | |
| Execution | T1059 | Command and Scripting Interpreter |
| T1569 | System Services | |
| Persistence | T1136 | Create Account |
| Defense Evasion | T1562 | Impair Defenses |
| T1550 | Use Alternate Authentication Material | |
| T1078 | Valid Accounts | |
| T1140 | Deobfuscate/Decode Files or Information | |
| T1070 | Indicator Removal | |
| Credential Access | T1003 | OS Credential Dumping |
| T1555 | Credentials from Password Stores | |
| T1110 | Brute Force | |
| Discovery | T1046 | Network Service Discovery |
| T1135 | Network Share Discovery | |
| Lateral Movement | T1570 | Lateral Tool Transfer |
| T1021 | Remote Services | |
| Impact | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]