216.73.217.22

Fog Ransomware – Technical Analysis

· Published 21/10/2024 11:02 · Modified 21/10/2024 11:24

Export JSON

Essential information

Published
21/10/2024 11:02
Modified
21/10/2024 11:24
Tags
2024-10-21 cryptography encryption file-encryption fog ransomware multi-threading process-termination ransomware service-stopping vpn windows
Related entities
1 observables, 1 intrusion sets (apt), 8 techniques (mitre), 1 malware, 2 others

Description

A new called Fog has been identified, affecting education and recreation centers in the United States. The threat actors gain access through compromised credentials, disable Defender, and deploy the . Fog is a 32-bit EXE file compiled using Microsoft Visual C/C++. It uses debug messages, dynamically loads APIs, and decrypts its configuration from JSON format. The operates as a application, encrypting files and dropping ransom notes in each directory. It utilizes CryptoAPI for cryptographic operations, stops specific services, terminates blacklisted processes, and removes backups. Fog also employs various MITRE ATT&CK techniques for execution, discovery, defense evasion, and impact.

External references