Fog Ransomware, previously targeting education and recreational sectors, has shifted its focus to the financial industry. It gains access through compromised VPN credentials, uses techniques like “pass-the-hash” to escalate privileges, and disables security before encrypting files and deleting backups. The attackers also exfiltrate sensitive data for double extortion, threatening to leak it if ransom demands aren’t met. Fog’s rapid evolution highlights its growing sophistication and expanded targeting strategies.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox