FOG Ransomware Spread by Cybercriminals Claiming Ties to DOGE

April 21, 2025, 1:15 p.m.

Description

An investigation of nine malware samples revealed FOG ransomware being distributed by cybercriminals impersonating the Department of Government Efficiency (DOGE). The ransomware, spread via email and phishing attacks, is concealed in a ZIP file named 'Pay Adjustment.zip'. The infection chain involves a multi-stage operation, downloading various scripts and executables. The ransomware checks for sandbox environments, decrypts its payload, and drops a ransom note. FOG ransomware has targeted multiple sectors, including technology, education, manufacturing, and transportation. The campaign either involves original FOG operators using DOGE references to troll users or other actors embedding FOG ransomware for impersonation purposes.

Date

  • Created: April 21, 2025, 12:43 p.m.
  • Published: April 21, 2025, 12:43 p.m.
  • Modified: April 21, 2025, 1:15 p.m.

Indicators

  • dec35a94e4986765aa69635d02f09f58bfc8756b8fd5e1e9183b26eef0118667
  • dc5370e1ab5b26ff04b9e34c6dbb37cf6c600b7ac9a394fd519b547b37a6d2d5
  • 8e209e4f7f10ca6def27eabf31ecc0dbb809643feaecb8e52c2f194daa0511aa
  • 44b7eebf7a26d466f9c7ad4ddb058503f7066aded180ab6d5162197c47780293
  • 3d2cbef9be0c48c61a18f0e1dc78501ddabfd7a7663b21c4fcc9c39d48708e91
  • 100cbf5578cfd03950c8606c6131a85635a8278696d3d64ecb629fa09af449e9

Attack Patterns

Additional Informations

  • Consumer Services
  • Business Services
  • Retail
  • Technology
  • Healthcare
  • Transportation
  • Education
  • Manufacturing
  • United States of America