FOG Ransomware Spread by Cybercriminals Claiming Ties to DOGE
April 21, 2025, 1:15 p.m.
Description
An investigation of nine malware samples revealed FOG ransomware being distributed by cybercriminals impersonating the Department of Government Efficiency (DOGE). The ransomware, spread via email and phishing attacks, is concealed in a ZIP file named 'Pay Adjustment.zip'. The infection chain involves a multi-stage operation, downloading various scripts and executables. The ransomware checks for sandbox environments, decrypts its payload, and drops a ransom note. FOG ransomware has targeted multiple sectors, including technology, education, manufacturing, and transportation. The campaign either involves original FOG operators using DOGE references to troll users or other actors embedding FOG ransomware for impersonation purposes.
External References
Tags
Date
- Created: April 21, 2025, 12:43 p.m.
- Published: April 21, 2025, 12:43 p.m.
- Modified: April 21, 2025, 1:15 p.m.
Indicators
- dec35a94e4986765aa69635d02f09f58bfc8756b8fd5e1e9183b26eef0118667
- dc5370e1ab5b26ff04b9e34c6dbb37cf6c600b7ac9a394fd519b547b37a6d2d5
- 8e209e4f7f10ca6def27eabf31ecc0dbb809643feaecb8e52c2f194daa0511aa
- 44b7eebf7a26d466f9c7ad4ddb058503f7066aded180ab6d5162197c47780293
- 3d2cbef9be0c48c61a18f0e1dc78501ddabfd7a7663b21c4fcc9c39d48708e91
- 100cbf5578cfd03950c8606c6131a85635a8278696d3d64ecb629fa09af449e9
Additional Informations
- Consumer Services
- Business Services
- Retail
- Technology
- Healthcare
- Transportation
- Education
- Manufacturing
- United States of America