fog

Ransomware
Sourceransomware.live

About the group

Fog, which uses the .flocked extension for encrypted files, was first observed in May in campaigns by Storm-0844, a threat actor known for distributing Akira. By June, Storm-0844 was deploying Fog more than Akira.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Impact and victims

The group fog has 6 known ransomware victims. See the most affected sectors and countries and recent victims.

6known victims
6in Brazil
5sectors hit
Most attacked sectors
Manufacturing2
Professional Services1
Retail & E-Commerce1
Technology1
Transportation1
Most affected countries
🇧🇷 Brasil6
Recent victims
Pampili (pampili.com.br)Retail & E-Commerce · BR · 2025-03-04
Grupo Baston Aerossol (baston.com.br)Manufacturing · BR · 2025-03-04
Top SystemsTechnology · BR · 2025-02-06
Industria e Comercio Jolitex Ltda (jolitex.com)Manufacturing · BR · 2024-12-23
Ouro Verde (ouroverde.net.br)Transportation · BR · 2024-12-17
GSR Andrade Architects (gsr-andrade.com)Professional Services · BR · 2024-11-06

fog uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →