Target Industry

FOG ransomware targets technology, education, manufacturing, and transportation. 

Overview

FOG ransomware is being distributed by cybercriminals under the guise of the Department of Government Efficiency (DOGE). The ransomware is spread through email and phishing attacks, often disguised as a “Pay Adjustment.zip” file. Since January, FOG ransomware has affected 100 victims, with the highest number of incidents occurring in February. Additionally, the cybercriminals offer victims a free decryption key if they help spread the malware to others. 

Impact

The impact of FOG ransomware has been significant, affecting various sectors and causing substantial disruptions. Cybercriminals have exploited DOGE to add credibility to their phishing attacks, increasing the likelihood of successful infections. For victims caught up in this campaign they may have faced data encryption, operational downtime, and potential financial losses due to ransom demands. 

Exploitation

FOG ransomware is distributed via an LNK file disguised as a PDF, which executes a PowerShell script. The script downloads additional malicious files and performs various operations, including privilege escalation and data exfiltration. The ransomware payload includes scripts for collecting system information and sending it to a remote server. It also includes tools for privilege escalation and a QR code directing to a Monero cryptocurrency wallet. 

Indicators of Compromise

Here are the top three Indicators of Compromise (IoCs) for FOG ransomware: 

  • URLs: 
  • hxxp[:]//xbkv2qey6u3gd3qxcojynrt4h5sgrhkar6whuo74wo63hijnn677jnyd[.]onion  
  • hxxp[:]//xbkv2qey6u3gd3qxcojynrt4h5sgrhkar6whuo74wo63hijnn677jnyd[.]onion/posts 
  • File servers: 
  • hxxp[:]//hlbqbuy2bo3onn6h6eq7pbci24kughiaw4rkxrewidnqma3hwwgt2ead[.]onion  
  • hxxp[:]//44dz7r5uduhihaks7m62vztthp5s7thokbgeida7usm4rvakriuvk3yd[.]onion/ 
  • hxxp[:]//nw5zrjqarckmsf22rrgo5yooelpnn5raxhesuhrpzceqibmjwanbbaad[.]onion/ 
  • Chat server: 
  • hxxps[:]//xql562evsy7njcsngacphc2erzjfecwotdkobn3m4uxu2gtqh26newid[.]onion/ 

 

The hash values (SHA-256) correspond to the URLs, and the other hash values have also been associated with FOG ransomware: 

  • 44b7eebf7a26d466f9c7ad4ddb058503f7066aded180ab6d5162197c47780293 
  • hxxps://hilarious-trifle-d9182e.netlify.app/lootsubmit[.]ps1    
  • 3d2cbef9be0c48c61a18f0e1dc78501ddabfd7a7663b21c4fcc9c39d48708e91 
  • hxxps://hilarious-trifle-d9182e.netlify.app/trackerjacker[.]ps1  
  • dc5370e1ab5b26ff04b9e34c6dbb37cf6c600b7ac9a394fd519b547b37a6d2d5 
  • hxxps://hilarious-trifle-d9182e.netlify.app/qrcode[.]png  
  • 100cbf5578cfd03950c8606c6131a85635a8278696d3d64ecb629fa09af449e9 
  • hxxps[:]//hilarious-trifle-d9182e[.]netlify[.]app/ktool[.]exe  
  • dec35a94e4986765aa69635d02f09f58bfc8756b8fd5e1e9183b26eef0118667 
  • 8e209e4f7f10ca6def27eabf31ecc0dbb809643feaecb8e52c2f194daa0511aa 

Containment, Mitigations & Remediations

To mitigate against FOG ransomware, it is highly recommended to: 

  • Be aware about the dangers of phishing attacks and the importance of not opening suspicious email attachments 
  • Regularly back up critical data and ensure backups are stored offline to prevent ransomware from encrypting them 
  • Regularly update and patch all software to close potential security vulnerabilities 
  • Use endpoint protection tools to detect and prevent the execution of malicious scripts 
  • Employ advanced email filtering solutions to detect and block malicious attachments 
  • Monitor network traffic for unusual activity and employ intrusion detection systems to identify and respond to data exfiltration attempts.  

Threat Group

According to SentinelOne, the FOG ransomware group was first observed in the wild in April 2024, but it has been actively distributing the malware since January 2025. It was initially observed as targeting educational organisations in the US before expanding to other sectors and countries. The ransom payment is typically demanded in cryptocurrency, such as Monero. 

Further Information

Trend Micro article 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content