Lifting the Fog: Investigating Fog Ransomware

Fog ransomware first appeared in May 2024 targeting US educational organizations. Darktrace’s investigation reveals a rapid attack cycle—initial access via compromised VPN credentials, rapid lateral movement, data exfiltration, and encryption, with C2 using remote-access tools such as AnyDesk and SplashTop. #FogRansomware #AnyDesk #SplashTop #MEGA

Keypoints

  • Fog ransomware first observed in May 2024, targeting US educational institutions.
  • Utilizes compromised VPN credentials for initial access to networks.
  • Rapid progression from access to file encryption in as little as 2 hours.
  • Key activities include enumeration, lateral movement, encryption, and data exfiltration.
  • Employs remote access tools like AnyDesk and SplashTop for command-and-control communication.
  • Exfiltration attempts suggest a double extortion tactic, threatening public exposure of sensitive data.
  • Darktrace’s Autonomous Response effectively mitigated some attacks by quarantining affected devices.

MITRE Techniques

  • [T1001] Data Obfuscation – Data obfuscation used in C2. Quote: (‘Used to obscure data during command-and-control communication.’)
  • [T1018] Remote System Discovery – Reconnaissance to identify systems within the network. Quote: (‘Reconnaissance to identify systems within the network.’)
  • [T1021.002] SMB/Windows Admin Shares – Lateral Movement within the network. Quote: (‘Utilized for lateral movement within the network.’)
  • [T1036.003] Rename System Utilities – Defense Evasion by renaming tools. Quote: (‘Used for evading detection by renaming tools.’)
  • [T1040] Network Sniffing – Gathering credentials and sensitive information from network traffic. Quote: (‘Gathering credentials and sensitive information from network traffic.’)
  • [T1041] Exfiltration Over C2 Channel – Exfiltrating data through established command and control channels. Quote: (‘Exfiltrating data through established command and control channels.’)
  • [T1074] Data Staged – Preparing data for exfiltration. Quote: (‘Preparing data for exfiltration.’)
  • [T1078] Valid Accounts – Utilizing compromised accounts for access and persistence. Quote: (‘Utilizing compromised accounts for access and persistence.’)
  • [T1080] Taint Shared Content – Manipulating shared content for lateral movement. Quote: (‘Manipulating shared content for lateral movement.’)
  • [T1083] File and Directory Discovery – Identifying files and directories for targeted attacks. Quote: (‘Identifying files and directories for targeted attacks.’)
  • [T1114] Email Collection – Gathering emails for further exploitation. Quote: (‘Gathering emails for further exploitation.’)
  • [T1119] Automated Collection – Automating the collection of sensitive data. Quote: (‘Automating the collection of sensitive data.’)
  • [T1135] Network Share Discovery – Identifying network shares for potential exploitation. Quote: (‘Identifying network shares for potential exploitation.’)
  • [T1190] Exploit Public-Facing Application – Exploiting vulnerabilities in public-facing applications for initial access. Quote: (‘Exploiting vulnerabilities in public-facing applications for initial access.’)
  • [T1200] Hardware Additions – Using hardware modifications for unauthorized access. Quote: (‘Using hardware modifications for unauthorized access.’)
  • [T1219] Remote Access Software – Using legitimate remote access software for command-and-control. Quote: (‘Using legitimate remote access software for command-and-control.’)
  • [T1486] Data Encrypted for Impact – Encrypting data to disrupt operations and demand ransom. Quote: (‘Encrypting data to disrupt operations and demand ransom.’)
  • [T1550.002] Pass the Hash – Using hashed credentials for lateral movement. Quote: (‘Using hashed credentials for lateral movement.’)
  • [T1567.002] Exfiltration to Cloud Storage – Transferring data to cloud storage services for exfiltration. Quote: (‘Transferring data to cloud storage services for exfiltration.’)
  • [T1570] Lateral Tool Transfer – Transferring tools between systems for lateral movement. Quote: (‘Transferring tools between systems for lateral movement.’)

Indicators of Compromise

  • [Executable File] Remote Access Management Tool – /AnyDesk.exe
  • [Domain] Exfiltration Domain – gfs302n515.userstorage.mega.co.nz
  • [Filename Extension] Fog Ransomware Extension – *.flocked
  • [Text File] Fog Ransom Note – readme.txt
  • [Onion Domain] Threat Actor’s Communication Channel – xql562evsy7njcsngacphcerzjfecwotdkobn3m4uxu2gtqh26newid.onion

Read more: https://darktrace.com/blog/lifting-the-fog-darktraces-investigation-into-fog-ransomware