Fog, which uses the .flocked extension for encrypted files, was first observed in May in campaigns by Storm-0844, a threat actor known for distributing Akira. By June, Storm-0844 was deploying Fog more than Akira. Known victims: 189 6 negotiation log(s) available, 2 ransom note(s) on file
Objectives
Executive Summary
The 'fog' threat actor is a medium-sophistication criminal group primarily engaged in ransomware activities, targeting organizations for financial gain since December 2021. They have successfully compromised over 189 victims and are known to use the '.flocked' file extension for encryption. Their operations demonstrate a clear focus on organizational gain through malicious ransom activities.
Goals & Targeting
'Fog' primarily aims to achieve financial gain through ransomware. They target a wide range of organizations without apparent sectoral bias, focusing instead on maximizing the volume of victims to enhance their illicit earnings. As an entry-level to medium-sophistication threat group, they likely focus on softer targets with weaker defenses.
Enhanced Description
'Fog', employing the .flocked file extension, emerged in May 2021. By June, it was observed more frequently than Akira in campaigns by the threat actor Storm-0844. 'Fog' is associated with financial gain through ransomware, leveraging encryption to extort victims. With 189 known victims and two negotiation logs available, this group has demonstrated significant operational persistence from late 2021 into March 2025. Their activities suggest a strategic shift or preference in malware deployment over previous tools like Akira. While specific targeting sectors or countries are unreported, the sheer number of victims indicates a broad targeting approach.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
'Fog' has been linked to multiple campaigns, primarily involving the deployment of ransomware viaStorm-0844. Their operational model includes targeting a wide range of organizations, reflecting an indiscriminate approach aimed at maximizing victim count for financial gain.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence with significant data gaps, particularly regarding exact TTPs beyond file encryption and hash data. No specific campaigns or tools other than 'Fog' are referenced.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
53
IOCs
0
Observed Data
0
Tactics