{"id":4623,"date":"2025-06-13T10:05:42","date_gmt":"2025-06-13T10:05:42","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/06\/13\/fog-ransomware-actors-exploits-pentesting-tools-to-exfiltrate-data-and-deploy-ransomware\/"},"modified":"2025-06-13T10:05:42","modified_gmt":"2025-06-13T10:05:42","slug":"fog-ransomware-actors-exploits-pentesting-tools-to-exfiltrate-data-and-deploy-ransomware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/06\/13\/fog-ransomware-actors-exploits-pentesting-tools-to-exfiltrate-data-and-deploy-ransomware\/","title":{"rendered":"Fog Ransomware Actors Exploits Pentesting Tools to Exfiltrate Data and Deploy Ransomware"},"content":{"rendered":"<p>    Fog Ransomware Actors Exploits Pentesting Tools to Exfiltrate Data and Deploy Ransomware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The Fog ransomware group has evolved beyond conventional attack methods, deploying an unprecedented arsenal of legitimate pentesting tools in a sophisticated May 2025 campaign targeting a financial institution in Asia.<\/p>\n<p>This latest operation marks a significant departure from typical ransomware tactics, incorporating employee monitoring software and open-source penetration testing frameworks previously unseen in the ransomware landscape.<\/p>\n<p>The attack demonstrates how threat actors are increasingly blurring the lines between espionage and financial cybercrime.<\/p>\n<p>The attackers maintained persistent access to the victim\u2019s network for approximately two weeks before deploying their ransomware payload, utilizing a diverse toolkit that included the legitimate Syteca employee monitoring software, GC2 command-and-control framework, Adaptix C2 Agent Beacon, and Stowaway <a href=\"https:\/\/cybersecuritynews.com\/how-to-choose-the-right-proxy-provider\/\" target=\"_blank\" rel=\"noreferrer noopener\">proxy tools<\/a>.<\/p>\n<p>Initial compromise vectors targeted Exchange Servers, though investigators could not definitively establish the precise entry point.<\/p>\n<p>The attackers leveraged these tools for reconnaissance, lateral movement, and data exfiltration, employing discovery commands such as <code>whoami<\/code>, <code>net use<\/code>, and network enumeration techniques to map the target environment.<\/p>\n<p>Symantec analysts <a href=\"https:\/\/www.security.com\/threat-intelligence\/fog-ransomware-attack\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the attack as particularly unusual due to the deployment of tools not commonly associated with ransomware operations.<\/p>\n<p>The GC2 tool, which utilizes Google Sheets or Microsoft SharePoint for command execution and file exfiltration, had previously been observed in APT41 operations but represents a novel addition to ransomware arsenals.<\/p>\n<p>The attackers configured GC2 to poll remote commands while maintaining stealth through legitimate cloud services, effectively bypassing traditional <a href=\"https:\/\/cybersecuritynews.com\/best-nginx-monitoring-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">network monitoring<\/a> solutions.<\/p>\n<p>Most notably, the attackers demonstrated exceptional persistence by establishing service-based backdoors several days after <a href=\"https:\/\/cybersecuritynews.com\/brain-cipher-ransomware-analysis-detection\/\" target=\"_blank\" rel=\"noreferrer noopener\">ransomware<\/a> deployment, creating a service named \u201cSecurityHealthIron\u201d with the description \u201cCollect performance information about an application by using command-line tools\u201d.<\/p>\n<p>This post-ransomware persistence mechanism suggests potential dual-purpose operations, where traditional ransomware activities may serve as cover for ongoing espionage activities.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Advanced Persistence and Dual-Purpose Operations<\/strong><\/h2>\n<p>The establishment of persistence mechanisms following ransomware deployment represents a paradigm shift in threat actor behavior.<\/p>\n<p>The creation of the SecurityHealthIron service using <code>sc create<\/code> commands indicates sophisticated planning beyond immediate financial gain.<\/p>\n<p>This technique, combined with process watchdog programs monitoring GC2 operations, suggests that Fog operators view ransomware as one component of broader <a href=\"https:\/\/cybersecuritynews.com\/collaborative-threat-intelligence-sharing\/\" target=\"_blank\" rel=\"noreferrer noopener\">intelligence<\/a> gathering campaigns rather than terminal attack objectives.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><strong>Automate threat response with ANY.RUN\u2019s TI Feeds\u2014Enrich alerts and block malicious IPs across all endpoints<\/strong>\u00a0-&gt;\u00a0<a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn_jun&amp;utm_medium=article&amp;utm_campaign=free-vs-paid-ti-feeds&amp;utm_content=plans&amp;utm_term=100625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Request full access<\/strong><\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/fog-ransomware-actors-exploits-pentesting-tools\/\">Fog Ransomware Actors Exploits Pentesting Tools to Exfiltrate Data and Deploy Ransomware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/fog-ransomware-actors-exploits-pentesting-tools\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fog Ransomware Actors Exploits Pentesting Tools to Exfiltrate Data and Deploy Ransomware The Fog ransomware group has evolved beyond conventional attack methods, deploying an unprecedented arsenal of legitimate pentesting tools in a sophisticated May 2025 campaign targeting a financial institution in Asia. This latest operation marks a significant departure from typical ransomware tactics, incorporating employee [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-4623","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4623"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4623"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4623\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4623"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4623"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4623"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}