Fog Ransomware — Victims, Campaigns & Activity

Threat entity extracted from intelligence sources

Frequency
10
occurrences
First Seen
November 6, 2025
Last Seen
June 23, 2026

Fog is a ransomware_group tracked across 7 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed November 6, 2025; most recent activity June 23, 2026.

Overview

Fog is a ransomware group known for running double-extortion campaigns and operating under a ransomware-as-a-service model with affiliate involvement. It typically targets enterprise networks by obtaining initial access and exfiltrating data before encryption, contributing to the ongoing evolution of ransomware threat activity. The current reporting ties focus to Cisco firewall exploit activity, underscoring Fog’s relevance in discussions about opportunistic network compromise and ransomware deployment.

Related Threat Clusters

Recent Intelligence Reports

  • CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd) — Isc.Sans.Edu · June 23, 2026
  • Veeam releases security update for critical backup server vulnerability | brief — Scworld · June 9, 2026
  • New Veeam vulnerability exposes backup servers to RCE attacks — Bleepingcomputer · June 9, 2026
  • New Veeam vulnerability exposes backup servers to RCE attacks — Bleepingcomputer · June 9, 2026
  • Europol IOCTA 2026 report flags shift to industrialised cybercrime powered by AI ... — Industrialcyber.Co · April 29, 2026
  • Fog Ransomware Attacking US Organizations Leveraging Compromised VPN Credentials — Cybersecuritynews · January 9, 2026
  • Fog Ransomware Targets U.S. Organizations via Compromised VPN Credentials — Gbhackers · January 9, 2026
  • Veeam patches three RCE flaws in backup systems, one critical — Scworld · January 7, 2026

CVSS v3.1 Breakdown