{
  "name": "Navigating Through The Fog",
  "slug": "navigating-through-the-fog",
  "description": "An open directory linked to a Fog ransomware affiliate was discovered, containing tools for reconnaissance, exploitation, lateral movement, and persistence. Initial access was gained through compromised SonicWall VPN credentials, while other tools facilitated credential theft and exploitation of Active Directory vulnerabilities. Persistence was maintained via AnyDesk, automated by a PowerShell script. Sliver C2 executables were used for command-and-control operations. The victims spanned multiple industries across Europe, North America, and South America, highlighting the affiliate's broad targeting scope. The toolkit included SonicWall Scanner, DonPAPI, Certipy, Zer0dump, and Pachine/noPac for various attack stages.",
  "published": "2025-04-28T02:42:32+00:00",
  "created_at": "2025-04-28T02:42:32+00:00",
  "modified_at": "2025-04-28T06:50:35+00:00",
  "created_at_opencti": "2025-04-28T02:42:32+00:00",
  "author": "",
  "confidence": null,
  "report_types": [],
  "labels": [],
  "tags": [
    "2025-04-28",
    "CVE-2020-1472",
    "CVE-2021-42278",
    "CVE-2021-42287",
    "active directory",
    "anydesk",
    "credential-theft",
    "fog ransomware",
    "lateral movement",
    "persistence",
    "ransomware",
    "sliver",
    "sonicwall",
    "vpn"
  ],
  "related_entities": {
    "observables": [
      {
        "id": "",
        "name": "194.48.154.79"
      }
    ],
    "malware": [
      {
        "id": "legacy:malware:105d5d5309fdb439",
        "name": "Fog ransomware",
        "slug": "fog-ransomware"
      },
      {
        "id": "c70c9980-18de-4208-93f5-0bd2dddeb40c",
        "name": "Sliver",
        "slug": "sliver"
      }
    ],
    "intrusion_sets": [
      {
        "id": "6afe54c8-24d5-4c29-bee6-2bfdb017ab5d",
        "name": "Fog ransomware group",
        "slug": "fog-ransomware-group"
      }
    ],
    "attack_patterns": [
      {
        "id": "b15c00da-c412-4429-900c-659de612baf5",
        "name": "T1543.003"
      }
    ],
    "vulnerabilities": [
      {
        "id": "",
        "name": "CVE-2021-42287"
      },
      {
        "id": "",
        "name": "CVE-2021-42278"
      },
      {
        "id": "",
        "name": "CVE-2020-1472"
      }
    ],
    "others": [
      {
        "id": "",
        "name": "Greece"
      },
      {
        "id": "",
        "name": "Italy"
      },
      {
        "id": "",
        "name": "Brazil"
      },
      {
        "id": "",
        "name": "United States of America"
      },
      {
        "id": "",
        "name": "Retail"
      },
      {
        "id": "",
        "name": "Technology"
      },
      {
        "id": "",
        "name": "Transportation"
      },
      {
        "id": "",
        "name": "Education"
      }
    ]
  },
  "external_refs": [
    "https://thedfirreport.com/2025/04/28/navigating-through-the-fog",
    "https://otx.alienvault.com/pulse/680f0738479d23f04a10d198"
  ]
}