fog
Fog, which uses the .flocked extension for encrypted files, was first observed in May in campaigns by Storm-0844, a threat actor known for distributing Akira. By June, Storm-0844 was deploying Fog more than Akira.
Fog is a ransomware group operated by Storm-0844, known for using the .flocked file extension for encryption.
Fog is a ransomware group that uses the .flocked extension for encrypted files, operated by Storm-0844, a threat actor previously known for distributing Akira ransomware. The actor primarily targets organizations for financial gain through ransomware operations. Key TTPs include file encryption, and while initial access vectors are not specified, they are likely associated with Storm-0844's established methods. Defenders should focus on detecting the .flocked file extension, creating detection rules based on Storm-0844’s prior Akira-related TTPs, and revisiting existing Akira indicators for potential overlap.
Fog, which uses the .flocked extension for encrypted files, was first observed in May in campaigns by Storm-0844, a threat actor known for distributing Akira. By June, Storm-0844 was deploying Fog more than Akira.
The Fog ransomware group uses the .flocked file extension for encrypted files.
The Fog ransomware is operated by Storm-0844, a group previously known for distributing Akira ransomware.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.