Target Industry
FOG ransomware targets technology, education, manufacturing, and transportation.
Overview
FOG ransomware is being distributed by cybercriminals under the guise of the Department of Government Efficiency (DOGE). The ransomware is spread through email and phishing attacks, often disguised as a “Pay Adjustment.zip” file. Since January, FOG ransomware has affected 100 victims, with the highest number of incidents occurring in February. Additionally, the cybercriminals offer victims a free decryption key if they help spread the malware to others.
Impact
The impact of FOG ransomware has been significant, affecting various sectors and causing substantial disruptions. Cybercriminals have exploited DOGE to add credibility to their phishing attacks, increasing the likelihood of successful infections. For victims caught up in this campaign they may have faced data encryption, operational downtime, and potential financial losses due to ransom demands.
Exploitation
FOG ransomware is distributed via an LNK file disguised as a PDF, which executes a PowerShell script. The script downloads additional malicious files and performs various operations, including privilege escalation and data exfiltration. The ransomware payload includes scripts for collecting system information and sending it to a remote server. It also includes tools for privilege escalation and a QR code directing to a Monero cryptocurrency wallet.
Indicators of Compromise
Here are the top three Indicators of Compromise (IoCs) for FOG ransomware:
- URLs:
- hxxp[:]//xbkv2qey6u3gd3qxcojynrt4h5sgrhkar6whuo74wo63hijnn677jnyd[.]onion
- hxxp[:]//xbkv2qey6u3gd3qxcojynrt4h5sgrhkar6whuo74wo63hijnn677jnyd[.]onion/posts
- File servers:
- hxxp[:]//hlbqbuy2bo3onn6h6eq7pbci24kughiaw4rkxrewidnqma3hwwgt2ead[.]onion
- hxxp[:]//44dz7r5uduhihaks7m62vztthp5s7thokbgeida7usm4rvakriuvk3yd[.]onion/
- hxxp[:]//nw5zrjqarckmsf22rrgo5yooelpnn5raxhesuhrpzceqibmjwanbbaad[.]onion/
- Chat server:
- hxxps[:]//xql562evsy7njcsngacphc2erzjfecwotdkobn3m4uxu2gtqh26newid[.]onion/
The hash values (SHA-256) correspond to the URLs, and the other hash values have also been associated with FOG ransomware:
- 44b7eebf7a26d466f9c7ad4ddb058503f7066aded180ab6d5162197c47780293
- hxxps://hilarious-trifle-d9182e.netlify.app/lootsubmit[.]ps1
- 3d2cbef9be0c48c61a18f0e1dc78501ddabfd7a7663b21c4fcc9c39d48708e91
- hxxps://hilarious-trifle-d9182e.netlify.app/trackerjacker[.]ps1
- dc5370e1ab5b26ff04b9e34c6dbb37cf6c600b7ac9a394fd519b547b37a6d2d5
- hxxps://hilarious-trifle-d9182e.netlify.app/qrcode[.]png
- 100cbf5578cfd03950c8606c6131a85635a8278696d3d64ecb629fa09af449e9
- hxxps[:]//hilarious-trifle-d9182e[.]netlify[.]app/ktool[.]exe
- dec35a94e4986765aa69635d02f09f58bfc8756b8fd5e1e9183b26eef0118667
- 8e209e4f7f10ca6def27eabf31ecc0dbb809643feaecb8e52c2f194daa0511aa
Containment, Mitigations & Remediations
To mitigate against FOG ransomware, it is highly recommended to:
- Be aware about the dangers of phishing attacks and the importance of not opening suspicious email attachments
- Regularly back up critical data and ensure backups are stored offline to prevent ransomware from encrypting them
- Regularly update and patch all software to close potential security vulnerabilities
- Use endpoint protection tools to detect and prevent the execution of malicious scripts
- Employ advanced email filtering solutions to detect and block malicious attachments
- Monitor network traffic for unusual activity and employ intrusion detection systems to identify and respond to data exfiltration attempts.
Threat Group
According to SentinelOne, the FOG ransomware group was first observed in the wild in April 2024, but it has been actively distributing the malware since January 2025. It was initially observed as targeting educational organisations in the US before expanding to other sectors and countries. The ransom payment is typically demanded in cryptocurrency, such as Monero.
Further Information













