Fog is a ransomware group known for running double-extortion campaigns and operating under a ransomware-as-a-service model with affiliate involvement.
Overview
Fog is a ransomware group known for running double-extortion campaigns and operating under a ransomware-as-a-service model with affiliate involvement. It typically targets enterprise networks by obtaining initial access and exfiltrating data before encryption, contributing to the ongoing evolution of ransomware threat activity. The current reporting ties focus to Cisco firewall exploit activity, underscoring Fog’s relevance in discussions about opportunistic network compromise and ransomware deployment.
Related Threat Clusters
-
CVE-2024-40766 Exploited by Ransomware Groups Targeting SonicWall Firewalls
CVE-2024-40766 is an improper access control vulnerability in SonicWall SonicOS affecting Gen 5, Gen 6, and Gen 7 firewalls. The vulnerability, with a CVSS score of 9.3, allows unauthorized access and can crash the…
2 articles · Updated June 23, 2026 -
Critical RCE Vulnerability in Veeam Backup Exposes Organizations to Attacks
Veeam has disclosed a critical vulnerability (CVE-2026-44963) affecting its Backup & Replication software, allowing authenticated domain users to execute remote code on domain-joined backup servers. This flaw impacts…
11 articles · Updated June 9, 2026 -
Ransomware Fuels Surge in Global Cyberattacks
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
1922 articles · Updated February 12, 2026 -
Fog Ransomware Targets US Educational and Recreation Sectors via VPN Credentials
The Fog ransomware variant has been identified as a significant threat to US organizations, particularly in the education and recreation sectors. Since early May 2024, Arctic Wolf Labs has reported that 80% of affected…
3 articles · Updated January 9, 2026 -
Veeam Backup & Replication Vulnerabilities Enable RCE Attacks
Veeam has issued security updates to address multiple vulnerabilities in its Backup & Replication software, including a critical remote code execution (RCE) flaw tracked as CVE-2025-59470. This vulnerability affects…
7 articles · Updated January 7, 2026 -
Cisco Warns of New Attack Variant Targeting Firewalls
Cisco Systems has issued a warning regarding a new attack variant targeting its Secure Firewall devices, leveraging vulnerabilities CVE-2025-20333 and CVE-2025-20362. These vulnerabilities could potentially lead to…
4 articles · Updated November 6, 2025 -
Cisco Firewalls Targeted by New Attack Variant Exploiting Critical Vulnerabilities
Cisco has reported ongoing attacks against its firewalls, specifically targeting vulnerabilities CVE-2025-20333 and CVE-2025-20362. These flaws allow remote code execution and unauthorized access, leading to potential…
20 articles · Updated November 14, 2025
Recent Intelligence Reports
- CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd) — Isc.Sans.Edu · June 23, 2026
- Veeam releases security update for critical backup server vulnerability | brief — Scworld · June 9, 2026
- New Veeam vulnerability exposes backup servers to RCE attacks — Bleepingcomputer · June 9, 2026
- New Veeam vulnerability exposes backup servers to RCE attacks — Bleepingcomputer · June 9, 2026
- Europol IOCTA 2026 report flags shift to industrialised cybercrime powered by AI ... — Industrialcyber.Co · April 29, 2026
- Fog Ransomware Attacking US Organizations Leveraging Compromised VPN Credentials — Cybersecuritynews · January 9, 2026
- Fog Ransomware Targets U.S. Organizations via Compromised VPN Credentials — Gbhackers · January 9, 2026
- Veeam patches three RCE flaws in backup systems, one critical — Scworld · January 7, 2026