Fog ransomware first appeared in May 2024 targeting US educational organizations. Darktrace’s investigation reveals a rapid attack cycle—initial access via compromised VPN credentials, rapid lateral movement, data exfiltration, and encryption, with C2 using remote-access tools such as AnyDesk and SplashTop. #FogRansomware #AnyDesk #SplashTop #MEGA
Keypoints
- Fog ransomware first observed in May 2024, targeting US educational institutions.
- Utilizes compromised VPN credentials for initial access to networks.
- Rapid progression from access to file encryption in as little as 2 hours.
- Key activities include enumeration, lateral movement, encryption, and data exfiltration.
- Employs remote access tools like AnyDesk and SplashTop for command-and-control communication.
- Exfiltration attempts suggest a double extortion tactic, threatening public exposure of sensitive data.
- Darktrace’s Autonomous Response effectively mitigated some attacks by quarantining affected devices.
MITRE Techniques
- [T1001] Data Obfuscation – Data obfuscation used in C2. Quote: (‘Used to obscure data during command-and-control communication.’)
- [T1018] Remote System Discovery – Reconnaissance to identify systems within the network. Quote: (‘Reconnaissance to identify systems within the network.’)
- [T1021.002] SMB/Windows Admin Shares – Lateral Movement within the network. Quote: (‘Utilized for lateral movement within the network.’)
- [T1036.003] Rename System Utilities – Defense Evasion by renaming tools. Quote: (‘Used for evading detection by renaming tools.’)
- [T1040] Network Sniffing – Gathering credentials and sensitive information from network traffic. Quote: (‘Gathering credentials and sensitive information from network traffic.’)
- [T1041] Exfiltration Over C2 Channel – Exfiltrating data through established command and control channels. Quote: (‘Exfiltrating data through established command and control channels.’)
- [T1074] Data Staged – Preparing data for exfiltration. Quote: (‘Preparing data for exfiltration.’)
- [T1078] Valid Accounts – Utilizing compromised accounts for access and persistence. Quote: (‘Utilizing compromised accounts for access and persistence.’)
- [T1080] Taint Shared Content – Manipulating shared content for lateral movement. Quote: (‘Manipulating shared content for lateral movement.’)
- [T1083] File and Directory Discovery – Identifying files and directories for targeted attacks. Quote: (‘Identifying files and directories for targeted attacks.’)
- [T1114] Email Collection – Gathering emails for further exploitation. Quote: (‘Gathering emails for further exploitation.’)
- [T1119] Automated Collection – Automating the collection of sensitive data. Quote: (‘Automating the collection of sensitive data.’)
- [T1135] Network Share Discovery – Identifying network shares for potential exploitation. Quote: (‘Identifying network shares for potential exploitation.’)
- [T1190] Exploit Public-Facing Application – Exploiting vulnerabilities in public-facing applications for initial access. Quote: (‘Exploiting vulnerabilities in public-facing applications for initial access.’)
- [T1200] Hardware Additions – Using hardware modifications for unauthorized access. Quote: (‘Using hardware modifications for unauthorized access.’)
- [T1219] Remote Access Software – Using legitimate remote access software for command-and-control. Quote: (‘Using legitimate remote access software for command-and-control.’)
- [T1486] Data Encrypted for Impact – Encrypting data to disrupt operations and demand ransom. Quote: (‘Encrypting data to disrupt operations and demand ransom.’)
- [T1550.002] Pass the Hash – Using hashed credentials for lateral movement. Quote: (‘Using hashed credentials for lateral movement.’)
- [T1567.002] Exfiltration to Cloud Storage – Transferring data to cloud storage services for exfiltration. Quote: (‘Transferring data to cloud storage services for exfiltration.’)
- [T1570] Lateral Tool Transfer – Transferring tools between systems for lateral movement. Quote: (‘Transferring tools between systems for lateral movement.’)
Indicators of Compromise
- [Executable File] Remote Access Management Tool – /AnyDesk.exe
- [Domain] Exfiltration Domain – gfs302n515.userstorage.mega.co.nz
- [Filename Extension] Fog Ransomware Extension – *.flocked
- [Text File] Fog Ransom Note – readme.txt
- [Onion Domain] Threat Actor’s Communication Channel – xql562evsy7njcsngacphcerzjfecwotdkobn3m4uxu2gtqh26newid.onion
Read more: https://darktrace.com/blog/lifting-the-fog-darktraces-investigation-into-fog-ransomware