Fog Ransomware intensifies its attacks by exposing victims’ IPs

Fog Ransomware intensifies its attacks by exposing IP addresses on the Dark Web, increasing the risks of regulatory sanctions. Kaspersky’s analysis of this tactic.

Fog Ransomware intensifies its attacks by exposing IP addresses on the Dark Web, increasing the risks of regulatory sanctions. Kaspersky’s analysis of this tactic.

 

Kaspersky researchers discovered

a new tactic used by the Fog Ransomware group, known for attacking various industries. Now, in addition to stealing data, the cybercriminals are linking their victims’ IP addresses with the stolen information and publishing them on the Dark Web.
This shift in extortion strategies makes the attacks more noticeable and easier to trace. By making IP addresses public, the attackers increase psychological pressure on victims and the risk of facing regulatory sanctions.

A Growing Business Model.

Ransomware as a Service (RaaS) is a business model where malware developers lease their ransomware and control infrastructure to other cybercriminals.
Fog Ransomware is one of these groups, which emerged in early 2024 and has attacked sectors such as education, recreation, and finance.
The group exploits compromised VPN credentials to access victims’ data, which is then quickly encrypted, sometimes within two hours. These attacks have affected both Windows and Linux systems.

Enhanced Extortion Tactics.

Previously, Fog Ransomware employed double extortion tactics, encrypting data and threatening to publicly expose it to pressure victims into paying the ransom.
However, its new strategy has gone further, becoming the first RaaS group to publicly expose the IP addresses and stolen data on the Dark Web after the attack.

Additional Risks for Victims.

In addition to increasing psychological pressure, the exposure of IP addresses can facilitate further cybercriminal activities, as it provides external threat actors with a potential entry point to compromised networks.
This could lead to subsequent attacks, such as credential stuffing or the use of botnets against already vulnerable organizations.
Fabio Assolini, Director of the Global Research and Analysis Team (GReAT) for Latin America at Kaspersky, explains in detail that:

“As ransomware operators face a decline in payments due to improved cybersecurity defenses and regulatory pressure, they seek to refine their extortion methods to maintain control over the victims. Public exposure of IP addresses along with data leaks could increase the likelihood that organizations will comply with ransom demands in future incidents. This tactic could also be a fear-based marketing strategy, where attackers display their brutality to intimidate potential victims into paying quickly.”

Security Recommendations.

To protect against ransomware, Kaspersky experts recommend several key measures:

  • Train employees with courses on the fundamentals of cybersecurity to raise awareness about threats and teach effective mitigation strategies.
  • Regularly back up critical data and systems to minimize the impact of ransomware attacks or data loss resulting from malware infections.
  • Implement advanced security solutions with threat detection and prevention capabilities, such as Kaspersky Next EDR Foundations, to protect the organization from ransomware and other types of malware.
  • Continuously access Threat Intelligence data to obtain crucial information that allows proactive protection against cyber threats, identify risks, and improve incident response.

 

Share:
Hosting Web
Most Read