Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Fog, which uses the .flocked extension for encrypted files, was first observed in May in campaigns by Storm-0844, a threat actor known for distributing Akira. By June, Storm-0844 was deploying Fog more than Akira. Known victims: 189 6 negotiation log(s) available, 2 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

The 'fog' threat actor is a medium-sophistication criminal group primarily engaged in ransomware activities, targeting organizations for financial gain since December 2021. They have successfully compromised over 189 victims and are known to use the '.flocked' file extension for encryption. Their operations demonstrate a clear focus on organizational gain through malicious ransom activities.

Goals & Targeting

'Fog' primarily aims to achieve financial gain through ransomware. They target a wide range of organizations without apparent sectoral bias, focusing instead on maximizing the volume of victims to enhance their illicit earnings. As an entry-level to medium-sophistication threat group, they likely focus on softer targets with weaker defenses.

Enhanced Description

'Fog', employing the .flocked file extension, emerged in May 2021. By June, it was observed more frequently than Akira in campaigns by the threat actor Storm-0844. 'Fog' is associated with financial gain through ransomware, leveraging encryption to extort victims. With 189 known victims and two negotiation logs available, this group has demonstrated significant operational persistence from late 2021 into March 2025. Their activities suggest a strategic shift or preference in malware deployment over previous tools like Akira. While specific targeting sectors or countries are unreported, the sheer number of victims indicates a broad targeting approach.

Key Capabilities

  • Ransomware
  • File encryption with .flocked extension

MITRE ATT&CK Tactics

Exfiltration
Data Destruction
Credential Access
Disruption
Collection

ATT&CK Techniques

T1059.003
T1078
T1086
T1485
T1802

Software / Tooling

Fog ransomware

Campaigns & Victims

'Fog' has been linked to multiple campaigns, primarily involving the deployment of ransomware viaStorm-0844. Their operational model includes targeting a wide range of organizations, reflecting an indiscriminate approach aimed at maximizing victim count for financial gain.

IOC Patterns

  • Malicious file hashes associated with .flocked encrypted files
  • .flocked file extension

Recommended Actions

  • Implement robust endpoint detection and response solutions to identify and block known ransomware signatures and behaviors.
  • Monitor network traffic for anomalies, such as unusual encrypted files or data exfiltration attempts.
  • Conduct regular backups of critical systems and ensure these backups are isolated from direct network access to prevent their corruption by ransomware.
  • Educate employees about phishing emails and limit macros in Office documents to mitigate possible infection vectors.

Suggested Tags

ransomware
financial-gain

Confidence Assessment

Moderate confidence with significant data gaps, particularly regarding exact TTPs beyond file encryption and hash data. No specific campaigns or tools other than 'Fog' are referenced.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

53

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
ransomware
financial-gain

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Dec 20, 2021
Last Seen
Mar 20, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.