216.73.216.6

Fog Ransomware: Unusual Toolset Used in Recent Attack

· Published 17/06/2025 18:18 · Modified 18/06/2025 12:27

Export JSON

Essential information

Published
17/06/2025 18:18
Modified
18/06/2025 12:27
Tags
2025-06-12 2025-06-17 CVE-2024-40711 asia data theft employee monitoring software espionage financial institution fog fog ransomware lateral movement pentesting tools persistence unusual toolset
Related entities
22 techniques (mitre), 1 malware, 1 others

Description

A in was targeted by in May 2025, using an atypical toolset including legitimate and open-source . The attackers deployed Syteca, GC2, Adaptix, and Stowaway, which are uncommon in ransomware attacks. They remained on the network for two weeks before deploying the ransomware and unusually established afterward. The attack involved , , and attempts to delete evidence. The use of these tools and the suggest possible motives alongside the ransomware deployment. This incident highlights the importance of guarding against such sophisticated and unusual attack methodologies.

External references