Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Fog

Fog, which uses the .flocked extension for encrypted files, was first observed in May in campaigns by Storm-0844, a threat actor known for distributing Akira. By June, Storm-0844 was deploying Fog more than Akira.
External information

Victims
189
 
First Discovered
2024-07-16
victim
Last Discovered
2025-03-20
victim
Inactive Since
1yr
more than
Avg Delay
57.4
days
Infostealer
37.7%
victims with domain
Countries
35
hit
View Victims on World Map View Group Statistics

Known Locations (2)
Favicon Title Type Available Last Visit Server Info FQDN
favicon 500 Internal Server Error No 2026-04-28T07:23:51 xql562evsy7njcsngacphc2erzjfecwotdkobn3m4uxu2gtqh26newid.onion
favicon Blog No 2026-04-28T07:26:25 xbkv2qey6u3gd3qxcojynrt4h5sgrhkar6whuo74wo63hijnn677jnyd.onion

Target
Top 5 Activity Sectors
  • Technology 52
  • Education 38
  • Business Services 27
  • Manufacturing 22
  • Transportation/Logistics 10
Top 5 Countries
  • US flag United States 76
  • DE flag Germany 15
  • FR flag France 7
  • BR flag Brazil 6
  • AU flag Australia 6

Heatmap

Ransom Notes (2)

Tools Used
This information is provided by Ransomware-Tool-Matrix
Discovery RMM Tools Defense Evasion Credential Theft OffSec Networking LOLBAS Exfiltration
Advanced Port Scanner

SharpShares

SoftPerfect NetScan




AnyDesk












DonPAPI

Veeam-Get-Creds





Certipy

Impacket

Metasploit

NetExec

Orpheus

Sliver

Zer0dump
Powercat

Proxychains





PsExec













Negotiation Chats (6)
20240517 27 msgs
20240729 144 msgs
20240830 73 msgs
20240910 26 msgs
20240927 60 msgs
20241119 3 msgs

YARA Rules (1)

Indicators of Compromise (IoCs) (53)
Hash MD5 53
Type IOC
Hash MD5 07c6b4756715d73304ec0ebc951dddad
Hash MD5 09127f6b39c0c6aab163f010b7086acc
Hash MD5 0a6dd4eee2a0629d1da62f248a17ec80
Hash MD5 18f9eebf70db818c0f2a3c865f7132ee
Hash MD5 1a0a919dff09f63366f27f5e4c865d75
Hash MD5 21c244771422cf24ef49cdaf2b437c12
Hash MD5 240eb6d3415de2284e03ba8a586ed724
Hash MD5 25a14b8104eb50d56c46df79b0df37bf
Hash MD5 3226adfad6c5d31065347fbd2bda10e2
Hash MD5 4215b5ce20e033aeed7c56ae2e0eec60
Hash MD5 470a328ad3705d0c6866a48912a3f718
Hash MD5 4d5bec4d9d32e00c7d0b9d89e3948c8f
Hash MD5 4e9c72ca533aff19b5beaa0dd0df9276
Hash MD5 517ac3f7fc52792734b9a00a57cc5ae4
Hash MD5 5e1eec7d018f2dbd1280cd0c238e830d
Hash MD5 617d79c02ebac68b613d5b7cdbf001fd
Hash MD5 6195c398e48d65c5e33278a01089a45b
Hash MD5 64433a8a138c62661da2ccf552483c33
Hash MD5 6e48a67e0005cd6299d585314830af69
Hash MD5 7b795e5db82f25b8261d70048b2c3940
Hash MD5 7cc06e17a31673726f8fb94789252a93
Hash MD5 7d5b84b38766dacb04066d56908097b9
Hash MD5 83c419015c4d8df7cb1a208546ddb6f6
Hash MD5 868d8f2e942dd73b8ba9022fe7676032
Hash MD5 890fef6aa06bce73db52ee3087fa2a0e
Hash MD5 8b157ad42fa665d263904052f56a009b
Hash MD5 8f052170eb9c8cda872d07888753c5e7
Hash MD5 935d7db2557d62a55a23b6020d42351c
Hash MD5 9bfa6efef31916adcb6d447b48434be5
Hash MD5 a4e7b94c88a041d5e9983a704053f01c
Hash MD5 a8c09a3ad7a8faab7be4d46bbec4e01a
Hash MD5 b1094be42cf05bdd38951c8bf5c83cfd
Hash MD5 b5e1521ea5ffa2d5ec13cef61ffe363d
Hash MD5 ba4039b27f64a90d1038905f8b8804d0
Hash MD5 bcd51ee1df396f07af0b0a345a6dbaf4
Hash MD5 be5af780a67635d1eae32bc959450aff
Hash MD5 bef7a4725f55879af412d32f0b3b06bb
Hash MD5 bfc3dfd07dcf918bb87126fac4c62e7c
Hash MD5 c18dd6b7d1acf12d39ebb017a21a4a3e
Hash MD5 cfabf91cef8cb93ca8f2da8492015e25
Hash MD5 cff6c948bfede2c14590bd5daacd96ef
Hash MD5 d14ec0d9f4c265174c54d0f949e006ea
Hash MD5 d16ec8c2dc42401f3acea469c128d981
Hash MD5 d72c3508cbb968c478e0bd91e0f11424
Hash MD5 da15ca8a6a316ee543ecc0cf4799700e
Hash MD5 dee2ecb51fbfa2f1de9dbe9a7524da12
Hash MD5 dfb38db3eeee3287524d4d3aacae8c45
Hash MD5 e1edeaf3a358e7c356592cf2fea83ecd
Hash MD5 ef031581f138375a47a683253fea8768
Hash MD5 f162816f1d7b0006cfa0bfaf95c492c4
Hash MD5 f6359f375ae370e15bfef366f238ee15
Hash MD5 f63c17d6753abb95d876f5c02dc57ad5
Hash MD5 fd471239a6c4314c4f5f2ea7cc8e5cd5

Victims (189)
Logo
Discovered: 2025-03-20 (1y ago)
[AI generated] Newtown Friends School is a private, co-educational day school located in Newtown, Pe…
Logo
Discovered: 2025-03-17 (1y ago)
<1 GB…
Logo
Discovered: 2025-03-13 (1y ago)  ·  Attack est.: 2025-03-12
111 GB…
Logo
Discovered: 2025-03-11 (1y ago)  ·  Attack est.: 2025-03-10
57 GB…
Logo
Discovered: 2025-03-10 (1y ago)
54.6 GB…
Logo
Discovered: 2025-03-06 (1y ago)
27.7 GB…
Logo
Discovered: 2025-03-06 (1y ago)
33 GB…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-03-05
Extract from The 19 biggest gitlabs…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-03-05
Extract from The 19 biggest gitlabs…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-03-05
Extract from The 19 biggest gitlabs…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-03-05
Extract from The 19 biggest gitlabs…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-03-05
Extract from The 19 biggest gitlabs…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-03-05
Extract from The 19 biggest gitlabs…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-02-01
Extract from The 19 biggest gitlabs…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-03-05
Extract from The 19 biggest gitlabs…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-03-05
Extract from The 19 biggest gitlabs…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-03-05
Extract from The 19 biggest gitlabs…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-03-05
Extract from The 19 biggest gitlabs…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-03-05
Extract from The 19 biggest gitlabs…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-03-05
Extract from The 19 biggest gitlabs…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-03-05
Extract from The 19 biggest gitlabs…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2021-12-20
Extract from The 19 biggest gitlabs…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-03-05
Extract from The 19 biggest gitlabs…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-03-05
Extract from The 19 biggest gitlabs…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-03-05
Extract from The 19 biggest gitlabs…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2023-07-12
Extract from The 19 biggest gitlabs…
Logo
Discovered: 2025-03-05 (1y ago)
No description available
Logo
Discovered: 2025-03-04 (1y ago)
36.3 GB…
Logo
Discovered: 2025-03-04 (1y ago)
88.3 GB…
Logo
Discovered: 2025-03-03 (1y ago)
23.5 GB…
Logo
Discovered: 2025-02-26 (1y ago)
[AI generated] It seems there is a bit of confusion in the request as GitLab, Synelixis Solutions, I…
Logo
Discovered: 2025-02-23 (1y ago)
Extract from Gitlabs: Naphix, WDNA, Bayteq - Bayteq is a technology partner specializing in software…
Logo
Discovered: 2025-02-23 (1y ago)
Extract from Gitlabs: Naphix, WDNA, Bayteq - WDNA (Wireless Domestic Network Auditors) is a Spanish …
Logo
Discovered: 2025-02-23 (1y ago)
Extract from Gitlabs: Naphix, WDNA, Bayteq - gitlab…
Logo
Discovered: 2025-02-23 (1y ago)
No description available
Logo
Discovered: 2025-02-19 (1y ago)  ·  Attack est.: 2023-09-28
Extract from Gitlabs: Next TI, VISEO, Hochschule Trier - Hochschule Trier is a German university of …
Logo
Discovered: 2025-02-19 (1y ago)
Extract from Gitlabs: Next TI, VISEO, Hochschule Trier - VISEO is a global technology company offeri…
Logo
Discovered: 2025-02-19 (1y ago)
Extract from Gitlabs: Next TI, VISEO, Hochschule Trier: Next TI is an Indonesian IT solutions compan…
Logo
Discovered: 2025-02-19 (1y ago)
29,2 GB…
Logo
Discovered: 2025-02-19 (1y ago)
No description available
Logo
Discovered: 2025-02-16 (1y ago)
Extract from Gitlabs: Acqua development, QBurst, Pamyra.de- Pamyra.de is a platform that allows user…
Logo
Discovered: 2025-02-16 (1y ago)
Extract from Gitlabs: Acqua development, QBurst, Pamyra.de- QBurst is a full-service software develo…
Logo
Discovered: 2025-02-16 (1y ago)
Extract from Gitlabs: Acqua development, QBurst, Pamyra.de…
Logo
Discovered: 2025-02-16 (1y ago)
[AI generated] Gitlabs: Acqua development, QBurst, Pamyra.de refers to a combination of several tech…
Logo
Discovered: 2025-02-13 (1y ago)
Extract from Gitlabs: Omydoo, Ayomi, ADULLACT- ADULLACT is a French association that develops and pr…
Logo
Discovered: 2025-02-13 (1y ago)
Extract from Gitlabs: Omydoo, Ayomi, ADULLACT- Ayomi is a French platform that assists entrepreneurs…
Logo
Discovered: 2025-02-13 (1y ago)
Extract from Gitlabs: Omydoo, Ayomi, ADULLACT - Omydoo is a French company specializing in implement…
Logo
Discovered: 2025-02-13 (1y ago)
No description available
Logo
Discovered: 2025-02-13 (1y ago)
72.2…
Logo
Discovered: 2025-02-12 (1y ago)
Extract from Gitlabs: INGV, Spacemanic, Squeezer-software…
Logo
Discovered: 2025-02-12 (1y ago)
Extract from Gitlabs: INGV, Spacemanic, Squeezer-softwareSpacemanic is a Czech start-up that provide…
Logo
Discovered: 2025-02-12 (1y ago)
Extract from Gitlabs: INGV, Spacemanic, Squeezer-software - The Istituto Nazionale di Geofisica e Vu…
Logo
Discovered: 2025-02-12 (1y ago)
[AI generated] Gitlabs: INGV, Spacemanic, Squeezer-software is a conglomerate of three diverse speci…
Logo
Discovered: 2025-02-12 (1y ago)
6.5 GB…
Logo
Discovered: 2025-02-11 (1y ago)
5 GB…
Logo
Discovered: 2025-02-11 (1y ago)
171 GB…
Logo
Discovered: 2025-02-09 (1y ago)
Extract from Gitlabs: Universitatea Politehnica din Bucuresti, Maxvy Technologies Pvt, iRidge Inc.…
Logo
Discovered: 2025-02-09 (1y ago)
Extract from Gitlabs: Universitatea Politehnica din Bucuresti, Maxvy Technologies Pvt, iRidge Inc.…
Logo
Discovered: 2025-02-09 (1y ago)
Extract from Gitlabs: Universitatea Politehnica din Bucuresti, Maxvy Technologies Pvt, iRidge Inc.…
Logo
Discovered: 2025-02-07 (1y ago)
Extract from Gitlabs: Chalmers tekniska högskola, Fligno, 3SS…
Logo
Discovered: 2025-02-07 (1y ago)
Extract from Gitlabs: Chalmers tekniska högskola, Fligno, 3SS…
Logo
Discovered: 2025-02-07 (1y ago)
Extract from Gitlabs: Chalmers tekniska högskola, Fligno, 3SS…
Logo
Discovered: 2025-02-07 (1y ago)
No description available
Logo
Discovered: 2025-02-06 (1y ago)
Extract from Gitlabs: eConceptions, Top Systems, DIEM…
Logo
Discovered: 2025-02-06 (1y ago)
Extract from Gitlabs: eConceptions, Top Systems, DIEM…
Logo
Discovered: 2025-02-06 (1y ago)
Extract from Gitlabs: eConceptions, Top Systems, DIEM…
Logo
Discovered: 2025-02-06 (1y ago)
No description available
Logo
Discovered: 2025-02-04 (1y ago)  ·  Attack est.: 2025-01-30
Extract from Gitlabs: Prasaga, HE2B, Kombinat…
Logo
Discovered: 2025-02-04 (1y ago)  ·  Attack est.: 2025-01-30
Extract from Gitlabs: Prasaga, HE2B, Kombinat…
Logo
Discovered: 2025-02-04 (1y ago)  ·  Attack est.: 2025-01-30
Extract from Gitlabs: Prasaga, HE2B, Kombinat…
Logo
Discovered: 2025-02-04 (1y ago)  ·  Attack est.: 2025-01-31
Extract from Gitlabs: Professional Computer, X-Pans, Propulsion Academy AG…
Logo
Discovered: 2025-02-04 (1y ago)  ·  Attack est.: 2025-01-31
Extract from Gitlabs: Professional Computer, X-Pans, Propulsion Academy AG…
Logo
Discovered: 2025-02-04 (1y ago)  ·  Attack est.: 2025-01-31
Extract from Gitlabs: Professional Computer, X-Pans, Propulsion Academy AG…
Logo
Discovered: 2025-02-04 (1y ago)  ·  Attack est.: 2025-02-01
Extract from Gitlabs: PT. ITPRENEUR INDONESIA TECHNOLOGY, GFZ Helmholtz Centre for Geosciences, LUA …
Logo
Discovered: 2025-02-04 (1y ago)  ·  Attack est.: 2025-02-01
Extract from Gitlabs: PT. ITPRENEUR INDONESIA TECHNOLOGY, GFZ Helmholtz Centre for Geosciences, LUA …
Logo
Discovered: 2025-02-04 (1y ago)  ·  Attack est.: 2025-02-01
Extract from Gitlabs: PT. ITPRENEUR INDONESIA TECHNOLOGY, GFZ Helmholtz Centre for Geosciences, LUA …
Logo
Discovered: 2025-02-04 (1y ago)
Extract from Gitlabs: hemio.de, SOLEIL, Devlion…
Logo
Discovered: 2025-02-04 (1y ago)
Extract from Gitlabs: hemio.de, SOLEIL, Devlion…
Logo
Discovered: 2025-02-04 (1y ago)
Extract from Gitlabs: hemio.de, SOLEIL, Devlion…
Logo
Discovered: 2025-02-04 (1y ago)  ·  Attack est.: 2025-02-03
Extract from Gitlabs: Bolin Centre for Climate Research, X-lab group, Madia…
Logo
Discovered: 2025-02-04 (1y ago)  ·  Attack est.: 2025-02-03
Extract from Gitlabs: Bolin Centre for Climate Research, X-lab group, Madia…
Logo
Discovered: 2025-02-04 (1y ago)  ·  Attack est.: 2025-02-03
Extract from Gitlabs: Bolin Centre for Climate Research, X-lab group, Madia…
Logo
Discovered: 2025-02-04 (1y ago)
No description available
Logo
Discovered: 2025-02-03 (1y ago)
No description available
Logo
Discovered: 2025-02-03 (1y ago)
1.5 TB…
Logo
Discovered: 2025-01-30 (1y ago)
No description available
Logo
Discovered: 2025-01-29 (1y ago)
No description available
Logo
Discovered: 2025-01-29 (1y ago)
180 GB…
Logo
Discovered: 2025-01-24 (1y ago)
20 GB…
Logo
Discovered: 2025-01-24 (1y ago)
13 GB…
Logo
Discovered: 2025-01-23 (1y ago)
25.7 GB…
Logo
Discovered: 2025-01-14 (1y ago)
91 MB…
Logo
Discovered: 2025-01-14 (1y ago)
15 GB…
Logo
Discovered: 2025-01-14 (1y ago)
1.7 GB…
Logo
Discovered: 2025-01-10 (1y ago)
7.2 GB…
Logo
Discovered: 2025-01-07 (1y ago)
16.8 GB…
Logo
Discovered: 2024-12-26 (1y ago)
14.3 GB…
Logo
Discovered: 2024-12-25 (1y ago)
35 GB…
Logo
Discovered: 2024-12-23 (1y ago)
43.5 GB…
Logo
Discovered: 2024-12-23 (1y ago)
2.4 GB…
Logo
Discovered: 2024-12-20 (1y ago)
1 GB…
Logo
Discovered: 2024-12-20 (1y ago)
25.9 GB…
Logo
Discovered: 2024-12-20 (1y ago)
2.7 GB…
Logo
Discovered: 2024-12-20 (1y ago)  ·  Attack est.: 2024-12-19
5 GB…
Logo
Discovered: 2024-12-20 (1y ago)  ·  Attack est.: 2024-12-19
No description available
Logo
Discovered: 2024-12-18 (1y ago)
19 GB…
Logo
Discovered: 2024-12-17 (1y ago)
4 GB…
Logo
Discovered: 2024-12-16 (1y ago)
36 GB…
Logo
Discovered: 2024-12-11 (1y ago)
about 1 GB…
Logo
Discovered: 2024-12-05 (1y ago)
1 GB…
Logo
Discovered: 2024-12-02 (1y ago)
10 GB…
Logo
Discovered: 2024-11-29 (1y ago)
10,1 GB…
Logo
Discovered: 2024-11-28 (1y ago)
20 GB…
Logo
Discovered: 2024-11-28 (1y ago)
No description available
Logo
Discovered: 2024-11-28 (1y ago)
3 GB…
Logo
Discovered: 2024-11-27 (1y ago)
8,2 GB…
Logo
Discovered: 2024-11-26 (1y ago)
about 1 GB…
Logo
Discovered: 2024-11-26 (1y ago)
1,3 GB…
Logo
Discovered: 2024-11-21 (1y ago)
10,5 GB…
Logo
Discovered: 2024-11-19 (1y ago)
1 GB…
Logo
Discovered: 2024-11-19 (1y ago)
5,6 GB…
Logo
Discovered: 2024-11-15 (1y ago)
19 GB…
Logo
Discovered: 2024-11-06 (1y ago)
65 GB…
Logo
Discovered: 2024-10-31 (1y ago)
2,6 GB…
Logo
Discovered: 2024-10-30 (1y ago)
28 GB…
Logo
Discovered: 2024-10-30 (1y ago)
81 GB…
Logo
Discovered: 2024-10-28 (1y ago)  ·  Attack est.: 2024-10-25
5,1 GB…
Logo
Discovered: 2024-10-24 (1y ago)
25 GB…
Logo
Discovered: 2024-10-24 (1y ago)
45 GB…
Logo
Discovered: 2024-10-24 (1y ago)
27 GB…
Logo
Discovered: 2024-10-23 (1y ago)
10 GB…
Logo
Discovered: 2024-10-23 (1y ago)
37 GB…
Logo
Discovered: 2024-10-22 (1y ago)
10 GB…
Logo
Discovered: 2024-10-22 (1y ago)
71 GB…
Logo
Discovered: 2024-10-21 (1y ago)
118 GB…
Logo
Discovered: 2024-10-21 (1y ago)
102 GB…
Logo
Discovered: 2024-10-21 (1y ago)
3 GB…
Logo
Discovered: 2024-10-18 (1y ago)
16 GB…
Logo
Discovered: 2024-10-18 (1y ago)
3 GB…
Logo
Discovered: 2024-10-16 (1y ago)
27,6 GB…
Logo
Discovered: 2024-10-15 (1y ago)
20 GB…
Logo
Discovered: 2024-09-20 (1y ago)
10 GB…
Logo
Discovered: 2024-09-19 (1y ago)
30 GB…
Logo
Discovered: 2024-09-18 (1y ago)
250 GB…
Logo
Discovered: 2024-09-11 (1y ago)
No description available
Logo
Discovered: 2024-09-11 (1y ago)
469 GB…
Logo
Discovered: 2024-08-15 (1y ago)
No description available
Logo
Discovered: 2024-08-06 (1y ago)
20 GB…
Logo
Discovered: 2024-08-06 (1y ago)
22 GB…
Logo
Discovered: 2024-08-05 (1y ago)
22 GB…
Logo
Discovered: 2024-07-29 (1y ago)
30 GB…
Logo
Discovered: 2024-07-26 (1y ago)
10 GB…
Logo
Discovered: 2024-07-25 (1y ago)
18 GB…
Logo
Discovered: 2024-07-16 (1y ago)  ·  Attack est.: 2024-06-19
4GB…
Logo
Discovered: 2024-07-16 (1y ago)  ·  Attack est.: 2024-06-24
10 GB…
Logo
Discovered: 2024-07-16 (1y ago)  ·  Attack est.: 2024-07-07
19.4GB…
Logo
Discovered: 2024-07-16 (1y ago)  ·  Attack est.: 2024-07-04
95GB…
Logo
Discovered: 2024-07-16 (1y ago)  ·  Attack est.: 2024-07-04
60GB…
Logo
Discovered: 2024-07-16 (1y ago)  ·  Attack est.: 2024-07-11
9,5 GB…
Logo
Discovered: 2024-07-16 (1y ago)
10 GB…