Inactive ransomware operator
← All groupsFog
189 victims indexed · first seen 2 years ago · last activity 1 year ago
At a glance
- Status
- inactive
- First seen
- 2 years ago
- Last activity
- 1 year ago
- Onion sites
- 5 known endpoints
- Primary sector
- Technology · 37 hits
About
References
9 linksExternal sources curated by the MISP threat-intel community.
- ransomlook.io/group/fog
- kroll.com/en/publications/cyber/fog-ransomware-targets-higher-education
- broadcom.com/support/security-center/protection-bulletin/fog-ransomware
- sentinelone.com/anthology/fog/
- blog.barracuda.com/2025/04/29/a-closer-look-at-fog-ransomware
- trendmicro.com/en_us/research/25/d/fog-ransomware-concealed-within-binary-loaders-linking-themselve.html
- securitymagazine.com/articles/101694-fog-ransomware-group-uses-unconventional-toolset-new-research-finds
- areteir.com/static/FOG_Ransomware.pdf
- assets.kpmg.com/content/dam/kpmgsites/in/pdf/2024/11/kpmg-ctip-fog-ransomware-19-nov-2024.pdf.coredownload.inline.pdf
Timeline
9 monthsTop countries
Top sectors
MITRE ATT&CK
5 techniques · 4 tacticsTactics
Recent victims
Loading…
Onion infrastructure
5 known- http://xbkv2qey6u3gd3qxcojynrt4h5sgrhkar6whuo74wo63hijnn677jnyd.onion
- http://xbkv2qey6u3gd3qxcojynrt4h5sgrhkar6whuo74wo63hijnn677jnyd.onion/
- http://xql562evsy7njcsngacphc2erzjfecwotdkobn3m4uxu2gtqh26newid.onion
- http://xql562evsy7njcsngacphc2erzjfecwotdkobn3m4uxu2gtqh26newid.onion/
- https://xql562evsy7njcsngacphc2erzjfecwotdkobn3m4uxu2gtqh26newid.onion/
Source
Updated 1 year agoData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
