Ransomware Group intelligence
Fog
InactiveTrack Fog with 189 published victims and 3 known leak locations in a single intelligence view.
Overview
Fog is tracked by Breach House as a ransomware group with 189 published victims.
United States is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 3h ago | xbkv2qey6u3gd3qxcojynrt4h5sgrhkar6whuo74wo63hijnn677jnyd.onion |
| Leak location 3 | Onion service | Down checked 3h ago | xbkv2qey6u3gd3qxcojynrt4h5sgrhkar6whuo74wo63hijnn677jnyd.onion |
| Leak location 1 | Onion service | Down checked 3h ago | xql562evsy7njcsngacphc2erzjfecwotdkobn3m4uxu2gtqh26newid.onion |
Top Activity Sectors (14)
- Not identified 87
- Education 24
- Services 21
- IT 18
- Communication / Marketing 15
- Manufacturing / Engineering 5
- Finance / Legal / Insurance 4
- Healthcare / Pharma 3
- Public Sector 3
- Transportation / Travel / Logistics 3
- Construction / Real Estate 2
- Agriculture / Food 2
- Telecommunications 1
- Hospitality / Food & Beverage / Tourism 1
Typical Attacks (9)
▼MITRE ATT&CK does not currently catalogue Fog, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: fog executes PowerShell scripts to stage payloads and manipulate system processes during initial compromise.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: fog persists via Registry Run Keys to ensure automatic execution after system reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: fog disables antivirus tools and modifies security software configurations to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: fog deletes Volume Shadow Copies and backup directories via command-line utilities to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1135 Network Share Discovery Discovery
What they do: fog scans network shares using native tools to identify victim hosts and expand lateral movement.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: fog moves laterally through SMB/Windows Admin Shares to encrypt additional systems within the network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: fog exfiltrates stolen data via encrypted C2 channels before deploying ransomware.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: fog encrypts victim files using custom ransomware binaries targeting critical data stores.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: fog triggers system shutdown commands and service termination to maximize disruption and impact.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (16)
▼Software Fog has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Discovery & enumeration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
readme2.txt
If you are reading this, then you have been the victim of a cyber attack. We call ourselves Fog and we take responsibility for this incident. You can check out our blog where we post company data: xbkv2qey6u3gd3qxcojynrt4h5sgrhkar6whuo74wo63hijnn677jnyd.onion You might appear there if you opt out of our communication. We are the ones who encrypted your data and also copied some of it to our internal resource. The sooner you contact us, the sooner we can resolve this incident and get you back to work. To contact us you need to have Tor browser installed: 1. Follow this link: xql562evsy7njcsngacphc2erzjfecwotdkobn3m4uxu2gtqh26newid.onion 2. Enter the code: [snip] 3. Now we can communicate safely. If you are decision-maker, you will get all the details when you get in touch. We are waiting for you.
readme.txt
If you are reading this, then you have been the victim of a cyber attack. We call ourselves Fog and we take responsibility for this incident. We are the ones who encrypted your data and also copied some of it to our internal resource. The sooner you contact us, the sooner we can resolve this incident and get you back to work. To contact us you need to have Tor browser installed: 1. Follow this link: xql562evsy7njcsngacphc2erzjfecwotdkobn3m4uxu2gtqh26newid.onion 2. Enter the code: [snip] 3. Now we can communicate safely. If you are decision-maker, you will get all the details when you get in touch. We are waiting for you.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (189)
Search, filter and paginate the victim timeline for Fog. Showing 101–189 of 189.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Buttery (butterycompany.com) id16644 View details | United States | Services | ||
|
1.7 GB |
|||||
| Ransomware | OmniRide (omniride.com) id16570 View details | United States | Other | ||
|
7.2 GB |
|||||
| Ransomware | Saint-Bar (saintbar.be) id16529 View details | Belgium | Hospitality / Food & Beverage / Tourism | ||
|
16.8 GB |
|||||
| Ransomware | Ober Mountain (OberGatlinburg.com) id16408 View details | United States | Other | ||
|
14.3 GB |
|||||
| Ransomware | Aroma Housewares Co (Aromaco.com) id16394 View details | United States | Other | ||
|
35 GB |
|||||
| Ransomware | RODS Surveying (rods.cc) id16287 View details | Australia | Other | ||
|
43.5 GB |
|||||
| Ransomware | Forum Architecture & Interior Design (forumarchitecture.com) id16283 View details | United States | Construction / Real Estate | ||
|
5.7 GB |
|||||
| Ransomware | Gallade Chemical (galladechem.com) id16282 View details | United States | Manufacturing / Engineering | ||
|
2.4 GB |
|||||
| Ransomware | Industria e Comercio Jolitex Ltda (jolitex.com) id16281 View details | Brazil | Services | ||
|
23 GB |
|||||
| Ransomware | Schenkelberg - Die Medienstrategen (schenkelberg-druck.de) id16229 View details | Germany | Other | ||
|
6.8 GB |
|||||
| Ransomware | Village Community School (vcsnyc.org) id16228 View details | United States | Education | ||
|
1 GB |
|||||
| Ransomware | Circle Electric (circleelectric.com) id16227 View details | United States | Other | ||
|
25.9 GB |
|||||
| Ransomware | Howell Township Public Schools (howell.k12.nj.us) id16224 View details | United States | Education | ||
|
14.2 GB |
|||||
| Ransomware | EP Holdings (epholdingsinc.com) id16223 View details | United States | Services | ||
|
2.7 GB |
|||||
| Ransomware | Jet Edge (jetedgewaterjets.com) id16208 View details | United States | Other | ||
|
5 GB |
|||||
| Ransomware | Energy Capital Credit Union (eccu.net) id16207 View details | United States | Finance / Legal / Insurance | ||
|
No additional victim description available. |
|||||
| Ransomware | Vroninks Ricker Weyts & Sacre- Notaires (notassoc.be) id16178 View details | Belgium | Other | ||
|
15 GB |
|||||
| Ransomware | Reliance Connects (relianceconnects.com) id16177 View details | United States | Other | ||
|
19 GB |
|||||
| Ransomware | SpeedLine Solutions (speedlinesolutions.com) id16140 View details | Canada | Services | ||
|
6 GB |
|||||
| Ransomware | Ouro Verde (ouroverde.net.br) id16137 View details | Brazil | Other | ||
|
4 GB |
|||||
| Ransomware | Cognity (cognity.gr) id16111 View details | Greece | Other | ||
|
36 GB |
|||||
| Ransomware | Waverley Christian College (wcc.vic.edu.au) id16110 View details | Australia | Education | ||
|
5 GB |
|||||
| Ransomware | Planters Telephone Cooperative (planters.net) id15986 View details | United States | Other | ||
|
about 1 GB |
|||||
| Ransomware | Dorner (dorner-gmbh.de) id15874 View details | Germany | Other | ||
|
1 GB |
|||||
| Ransomware | Conlin's Pharmacy (conlinspharmacy.com) id15796 View details | Ireland | Healthcare / Pharma | ||
|
10 GB |
|||||
| Ransomware | Weld Racing (weldracing.com) id15762 View details | United States | Other | ||
|
10,1 GB |
|||||
| Ransomware | Chanas Assurances S.A. (chanasassurances.com) id15715 View details | Cameroon | Other | ||
|
6 GB |
|||||
| Ransomware | ALLTUB Group (alltub.com) id15714 View details | France | Services | ||
|
20 GB |
|||||
| Ransomware | Bedminster School (bedminsterschool.org) id15713 View details | United States | Education | ||
|
No additional victim description available. |
|||||
| Ransomware | WPM Pathology Laboratory (wpmpath.com) id15708 View details | Australia | Other | ||
|
3 GB |
|||||
| Ransomware | Gruber Tool & Die (grubertool.com) id15683 View details | United States | Other | ||
|
8,2 GB |
|||||
| Ransomware | Signal Health Washington (signalhealthwa.com) id15670 View details | United States | Healthcare / Pharma | ||
|
1 GB |
|||||
| Ransomware | Pioneer Urban Land & Infrastructure (pioneerurban.in) id15659 View details | India | Construction / Real Estate | ||
|
10 GB |
|||||
| Ransomware | Pinnacle Plastic Products (pinnacleplasitcporducts.com) id15658 View details | United States | Manufacturing / Engineering | ||
|
5,3 GB |
|||||
| Ransomware | Complete Recycling Services (completerecyclingservices.com) id15657 View details | United States | Services | ||
|
1,4 GB |
|||||
| Ransomware | Marketing Incentives (leinsterappointments.ie) id15655 View details | Ireland | Communication / Marketing | ||
|
about 1 GB |
|||||
| Ransomware | Metroline (metrolinedirect.com) id15654 View details | United States | Other | ||
|
1,3 GB |
|||||
| Ransomware | Hogan Mfg (hoganmfg.com) id15559 View details | United States | Other | ||
|
10,5 GB |
|||||
| Ransomware | Fifteenfortyseven Critical Systems Realty (1547realty.com) id15558 View details | United States | Services | ||
|
6 GB |
|||||
| Ransomware | Burkburnett Independent School District id15487 View details | United States | Education | ||
|
1 GB |
|||||
| Ransomware | Valley Planing Mill (valleyplaning.com) id15486 View details | United States | Other | ||
|
5,6 GB |
|||||
| Ransomware | Waters Truck and Tractor (waterstruck.com) id15397 View details | United States | Other | ||
|
3 GB |
|||||
| Ransomware | Vector Transport (vectortransport.com) id15349 View details | India | Transportation / Travel / Logistics | ||
|
19 GB |
|||||
| Ransomware | Cape Cod Regional Technical High School (capetech.us) id15181 View details | United States | IT | ||
|
6 GB |
|||||
| Ransomware | GSR Andrade Architects (gsr-andrade.com) id15180 View details | Brazil | Other | ||
|
65 GB |
|||||
| Ransomware | Askling Car (asklingbil.se) id15084 View details | Sweden | Other | ||
|
2,6 GB |
|||||
| Ransomware | Jillamy (jillamy.com) id15061 View details | United States | Other | ||
|
28 GB |
|||||
| Ransomware | SmartSource (smartsource-inc.com) id15059 View details | United States | Services | ||
|
81 GB |
|||||
| Ransomware | Jordan Public Schools (https://www.jordan.k12.mn.us/) id15036 View details | United States | Education | ||
|
11 GB |
|||||
| Ransomware | Sage Automotive Interior (sageautomotiveinteriors.com) id15035 View details | United States | Manufacturing / Engineering | ||
|
76 GB |
|||||
| Ransomware | Evergreen SD50 (evergreensd50.com) id15017 View details | Canada | Other | ||
|
5,1 GB |
|||||
| Ransomware | Cucamonga Valley Water District (cvwdwater.com) id14978 View details | United States | Other | ||
|
41 GB |
|||||
| Ransomware | Evergreen Local School District (evgvikings.org) id14977 View details | United States | Education | ||
|
5,1 GB |
|||||
| Ransomware | Value City NJ (valuecitynj.com) id14949 View details | United States | Public Sector | ||
|
25 GB |
|||||
| Ransomware | The Getz Group (getz.com.hk) id14948 View details | Hong Kong | Services | ||
|
45 GB |
|||||
| Ransomware | Apache Mills, Inc. (apachemills.com) id14942 View details | United States | Services | ||
|
27 GB |
|||||
| Ransomware | Goshen Central School District (gcsny.org) id14908 View details | United States | Education | ||
|
10 GB |
|||||
| Ransomware | Mar-Bal (mar-bal.com) id14907 View details | United States | Other | ||
|
37 GB |
|||||
| Ransomware | Lincoln University (lincolnu.edu) id14899 View details | United States | Education | ||
|
10 GB |
|||||
| Ransomware | Clear Connection (clearconnection.com) id14898 View details | United States | Other | ||
|
71 GB |
|||||
| Ransomware | Schweiger Transport (schweiger-gmbh.de) id14864 View details | Germany | Transportation / Travel / Logistics | ||
|
118 GB |
|||||
| Ransomware | Philadelphia Macaroni (philamacaroni.com) id14863 View details | United States | Other | ||
|
102 GB |
|||||
| Ransomware | Trimarc Financial (trimarc.com) id14860 View details | United States | Finance / Legal / Insurance | ||
|
3 GB |
|||||
| Ransomware | Fromm (FrommBeauty.com) id14821 View details | United States | Other | ||
|
16 GB |
|||||
| Ransomware | Ultra Tune (ultratune.com.au) id14820 View details | Australia | Other | ||
|
3 GB |
|||||
| Ransomware | Welker (welker.com) id14796 View details | United States | Other | ||
|
27,6 GB |
|||||
| Ransomware | Cordogan Clark and Associates (cordoganclark.com) id14795 View details | United States | Other | ||
|
107 GB |
|||||
| Ransomware | Food Sciences Corporation (foodsciences.com) id14789 View details | United States | Agriculture / Food | ||
|
86 GB |
|||||
| Ransomware | Central Pennsylvania Food Bank id14777 View details | United States | Finance / Legal / Insurance | ||
|
20 GB |
|||||
| Ransomware | Juice Generation id14394 View details | United States | Other | ||
|
10 GB |
|||||
| Ransomware | Sunrise Farms id14374 View details | Canada | Agriculture / Food | ||
|
30 GB |
|||||
| Ransomware | Prentke Romich Company id14356 View details | United States | Communication / Marketing | ||
|
250 GB |
|||||
| Ransomware | S. Walter Packaging id14256 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Clatronic International GmbH id14255 View details | Germany | Services | ||
|
469 GB |
|||||
| Ransomware | Seaway Manufacturing Corp. id13845 View details | United States | Manufacturing / Engineering | ||
|
No additional victim description available. |
|||||
| Ransomware | IOI Corporation Berhad id13700 View details | Malaysia | Services | ||
|
20 GB |
|||||
| Ransomware | Ziba Design id13699 View details | United States | Other | ||
|
22 GB |
|||||
| Ransomware | Hi-P International id13691 View details | Singapore | Services | ||
|
22 GB |
|||||
| Ransomware | BASF - Nunhems id13595 View details | Netherlands | Other | ||
|
30 GB |
|||||
| Ransomware | City of Cold Lake id13579 View details | Canada | Public Sector | ||
|
10 GB |
|||||
| Ransomware | Odessa College id13538 View details | United States | Education | ||
|
18 GB |
|||||
| Ransomware | Wichita State University Campus of Applied Sciences and Technology id13474 View details | Education | |||
|
10 GB |
|||||
| Ransomware | Geelong Lutheran College id13385 View details | Education | |||
|
4GB |
|||||
| Ransomware | Asbury Theological Seminary id13384 View details | Other | |||
|
10 GB |
|||||
| Ransomware | Djg Projects id13383 View details | Communication / Marketing | |||
|
19.4GB |
|||||
| Ransomware | Verweij Elektrotechniek id13382 View details | IT | |||
|
95GB |
|||||
| Ransomware | Alvin Independent School District id13381 View details | United States | Education | ||
|
60GB |
|||||
| Ransomware | West Allis-West Milwaukee School District id13380 View details | United States | Education | ||
|
9,5 GB |
|||||
| Ransomware | German University of Technology in Oman id13379 View details | Oman | IT | ||
|
10 GB |
|||||