Unusual toolset used in recent Fog Ransomware attack
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-40711 | Unauthenticated Deserialization RCE in Veeam Backup & Replication Veeam Backup & Replication contains a deserialization of untrusted data flaw (CWE-502) that allows an unauthenticated attacker to send a maliciously crafted serialized payload to the product's network-facing service and achieve remote code execution, with no privileges or user interaction required (CVSS 3.1: 9.8). Successful exploitation yields full code execution on the backup server with high impact on confidentiality, integrity and availability, and is especially valuable to attackers because backup infrastructure typically stores credentials and ransomware operators seek to destroy or encrypt backups before attacking production systems. Any organization running Veeam Backup & Replication is in scope; the provided data does not specify exact affected version ranges, so consult Veeam's advisory for the affected/fixed builds. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2024-10-17 with known ransomware use, a public proof-of-concept has been published by watchTowr, EPSS estimates a 90.4% probability of exploitation within 30 days (100th percentile), and the exploit has been reused in Frag ransomware attacks. Do: Apply Veeam's security updates immediately (the vendor released fixes for 18 flaws, including 5 critical ones); per the KEV required action, apply mitigations per Veeam's instructions or discontinue use if mitigations are unavailable. Until patched, restrict network access to the backup server from untrusted networks and remove unnecessary internet exposure. Given confirmed ransomware exploitation, also hunt for signs of compromise on backup servers and review backup job integrity and stored credentials. | 9.8 | 90% | KEV ransomware PoC |
| mass≈ hundreds of thousands of on-prem backup server deployments plausibly affected (tens of thousands internet-exposed) |
Full article403 words · extracted from securityaffairs.com · click to collapse

Fog ransomware operators used in a May 2025 attack unusual pentesting and monitoring tools, Symantec researchers warn.
In May 2025, attackers hit an Asian financial firm with Fog ransomware, using rare tools like Syteca monitoring software and pentesting tools GC2, Adaptix, and Stowaway. Symantec researchers pointed out that the use of these tools is unusual for ransomware campaigns. Notably, attackers created a service post-attack to maintain access, a rare persistence move. The attackers remained in the network for two weeks before launching the ransomware, signaling a more calculated, long-term strategy.
Fog ransomware has been active since at least May 2024 and focused on U.S. schools. The threat initially spread via compromised VPNs. By late 2024, it exploited a severe Veeam VBR flaw (CVE-2024-40711, CVSS 9.8). In April 2025, attackers shifted to email-based infections, with ransom notes mocking Elon Musk’s DOGE agency and offering free decryption if victims infected others, highlighting its evolving and provocative tactics.
The researchers were not able to determine the initial infection vector in a recent Fog ransomware attack, however, experts thought Exchange Servers were involved. Attackers deployed rare tools, including GC2, which uses Google Sheets or SharePoint for C2, and the Syteca monitoring tool, possibly for espionage. They used Stowaway for delivery, PsExec/SMBExec for lateral movement, and removed evidence post-use. Attackers used tools like Adaptix C2, FreeFileSync, MegaSync, and Process Watchdog to steal data, maintain persistence, and control.
This ransomware attack was highly unusual due to the atypical toolset used, the researchers speculte that tools like Syteca, GC2, Stowaway, and Adaptix C2 are rarely seen in such cases. The attackers also established persistence post-ransomware deployment, which is uncommon. These signs suggest the attack may have had espionage motives, with ransomware possibly used as a decoy or secondary goal.
“These factors mean it could be possible that this company may in fact have been targeted for espionage purposes, with the ransomware attack merely a decoy, or perhaps also deployed in an attempt by the attackers to make some money while also carrying out their espionage activity.” concludes the report that includes indicators of compromise. “What we can say with certainty is that this was an unusual toolset to see in a ransomware attack and is worth noting for businesses and corporations wanting to guard against attacks by malicious actors. “
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Fog ransomware)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/178969/malware/unusual-toolset-used-in-recent-fog-ransomware-attack.html