Fog ransomware attacks Use the employee monitoring tool to enter commercial networks


  • Fog ransomware using Syteca, a legitimate tool for employee monitoring, to register the keys and obtain passwords was observed.
  • He also used open source tools for the fall in payload and file exfiltration
  • The attack was “atypical,” says the researchers

Fog ransomware operators have expanded their arsenal to include legitimate and open source tools. This is, most likely, avoiding being detected before implementing the encrypper.

Symantec security researchers were recently brought to investigate a fog ransomware infection, and determined that hackers used Syteca, a legitimate tool for employee monitoring, during the attack.

Leave a Comment

Your email address will not be published. Required fields are marked *