Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Sunday, 14 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Unusual Toolset Behind Fog Ransomware Prompts Fresh Security Concerns

by The Gurus
June 13, 2025
in Featured
ransomware
Share on FacebookShare on Twitter

A newly discovered ransomware operation dubbed Fog is raising fresh concerns in the cybersecurity community after researchers found it leveraging a highly unusual mix of legitimate business software and open-source offensive security tools. The campaign, observed in June 2025, is part of a growing trend where cybercriminals are repurposing trusted programs to evade traditional detection methods and maximise their post-exploitation capabilities.

The attackers behind Fog aren’t simply deploying encryption and demanding payment; they’re laying the groundwork for stealth and persistence. Their toolkit includes Syteca employee-monitoring software, legitimate Windows utilities such as PsExec, and open-source penetration testing tools, including GC2 (a Google Sheets–based backdoor), Stowaway proxy, Sliver, and Ligolo. The combination of these tools allows the attackers to disable security systems, move laterally across networks, exfiltrate data, and monitor victims—all without triggering the usual alarms.

“Fog ransomware’s use of legitimate tools such as Syteca, combined with open-source pen testing tools, shows how attackers are finding new ways to bypass standard security measures,” said Nicolette Carklin, technical writer at SecureFlag. “It’s an indication that security can’t rely on traditional defences alone, and that secure development practices need to be part of the process to reduce these kinds of risks.”

Indeed, Fog’s stealthy nature is what sets it apart. Rather than exploiting exotic zero-day vulnerabilities, threat actors focus on exploiting avoidable weaknesses, including poor configuration, credential mismanagement, and unmonitored third-party components, all of which can be addressed if detected early in the development lifecycle.

“This attack is a pertinent reminder that many of these trusted tools exploit weaknesses that arise during software design, implementation, or configuration, areas where developer awareness can make a significant difference,” Carklin added. “For example, improper credential handling, overly permissive access rights, and unmonitored third-party components create openings for these kinds of post-exploitation tactics. The attackers’ use of pass-the-hash techniques and n-day exploits also highlights the need for secure configuration and prompt patching to close off potential entry points.”

The broader lesson from Fog is that trust can no longer be assumed, especially when it comes to widely used business applications. The campaign’s misuse of Syteca’s screen monitoring functionality, for example, turned a standard workplace productivity tool into a covert surveillance asset. This blurring of lines between legitimate software and malicious intent is emblematic of a new kind of ransomware playbook – one that doesn’t just demand a ransom but also quietly siphons data in the background.

“The real danger in this case isn’t the ransom note, it’s how Fog turns a simple screen-recorder into a hidden camera,” warned Akhil Mittal, senior security consulting manager at Black Duck. “Software is an essential driver of growth and innovation for every company; however, business apps we install on autopilot can suddenly become spy tools, which means trust is the weak spot. Security teams should maintain a live map of where every monitoring app is authorised to run and flag it the moment one appears in an unexpected location. For example, if HR software runs on a database server, that’s your warning sign.”

Nivedita Murthy, senior security consultant at Black Duck, added, “The use of legitimate open-source tools for malicious purposes is interesting. This reiterates the need to monitor the use of open-source software within the organisation. Open-source software can be updated by anyone unless the developer has restricted contributions to the code. It is also important to check how often these tools are updated and test them in a sandbox before implementing them within an organization’s network. As part of this test, you should also check for all calls outside of the network or any changes in privileges. It is also important to do a regular inventory audit of all tools and software installed on your system to check for any outliers.”

Murthy’s warning adds a layer of urgency to open-source governance practices, especially as many organisations adopt DevOps and shift-left security strategies. Without proper vetting, sandbox testing, and ongoing inventory monitoring, even seemingly harmless tools can become a foothold for ransomware actors seeking stealth and persistence.

This situational awareness is key. Experts agree that reactive cybersecurity strategies, those focused solely on detection and response, are no longer sufficient. Instead, prevention must begin at the earliest stages of software development, where misconfigurations and exploitable code paths can be designed out of the product altogether.

“Developing software with a ‘secure by design’ mindset and equipping developers to recognise potential abuse paths remains one of the most effective ways to limit the impact of such attacks,” Carklin said. “Prevention begins not only in the SOC but also at the design and development stages, where threat modeling, secure coding, and understanding attacker techniques can reduce the risk of exploitation later in the pipeline.”

Fog’s tactics are a powerful reminder that the battleground for ransomware is no longer limited to the endpoint. It now spans the entire software and infrastructure lifecycle, from the design decisions of developers to the deployment practices of IT teams and the trust assumptions of end users. Organisations hoping to defend against these next-generation threats must combine secure coding, proactive software governance, and continuous monitoring into a unified cybersecurity strategy.

ShareTweet
Previous Post

Keeper Security Named Overall Leader on GigaOm Radar Report for Enterprise Password Management

Next Post

Top 5 AI SOC Analyst Platforms to Watch out for in 2025

Recent News

Nagomi Control Brings CTEM Into Action

2 in 5 Organisations Experienced Cyber Incidents Tied to Suppliers in Past Year

June 12, 2026
Certes Research Warns Legacy Systems Are Biggest Barrier to Quantum Security Readiness

KnowBe4 Expands Gamified Training Library With Launch of “Spot the Vish” Game

June 12, 2026
Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

June 12, 2026
artificial-intelligence

The More Confident Organizations Are in Their AI Security, the More Likely They’ve Been Breached, New Research Finds

June 11, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol