Article Details

Scrape Timestamp (UTC): 2025-04-22 18:12:49.413

Source: https://www.theregister.com/2025/04/22/fog_ransomware_musk/

Original Article Text

Click to Toggle View

Fog ransomware channels Musk with demands for work recaps or a trillion bucks. In effect: 'Ha ha – the government is borked and so are you'. Ransomware scumbags - potentially those behind the Fog gang - are channeling their inner Elon Musk with their latest ransom note, spotted by researchers at Trend Micro. Victims not only have to cough up cash to feed the crime machine, but according to researchers, they're being trolled with the DOGE chief's infamous five-bullet-point demand to know what federal workers achieved that week. "Give me five bullet points on what you accomplished for work last week or you owe me a trillion dollars," a new line to Fog's updated ransom note reads. It refers to one of Musk's earliest policies after he was installed as the head of the US Department of Government Efficiency (DOGE), one that has been consistently applied across all of his companies. A memo was dispatched to workers demanding they outline five accomplishments from their past workweek in a bid to meet President Trump's request that federal staff be treated more aggressively. Following immediate pushback, other department heads made the controversial demand optional. According to the Washington Post, insiders expressed privacy concerns about the emails but were also worried they would lose their jobs if they didn't respond. As for why Fog decided to reference it in its new ransom note, Trend's researchers believe it's a sign of the criminals poking fun at victims and their sitting government. Other iterations of the note, which list several DOGE staffers, could also be seen as a reference to recent reports linking Edward Coristine – whose current role at DOGE is unknown – to the provision of tech support to a cybercrime gang. Reuters reported last month that Coristine, whose online handle is "bigballs," previously ran a company called DiamondCDN before joining DOGE, which was linked to the alleged provision of DDoS protection services to dataleak.fun – a site run by the now dormant EGodly group. Trend's researchers said it could have been Fog itself or another group using Fog's binaries, but in any case, they've dropped some useful intel and indicators of compromise on how to stop the ransomware. Fog hasn't been on the scene for too long – around a year – and not much is known about its makeup or origin, only that it targets Windows and Linux systems across various industries. Meanwhile, Musk's political career is also up in the air as speculation mounts about his role in the US government. The Washington Post reported this week that Musk may exit as soon as May, with the move believed to be driven by the billionaire's growing frustration with political attacks from the left. The plan is to still keep DOGE running and it is seen internally as an organization that shows how swiftly government departments can be radically overhauled, where necessary. But it isn't the success story many had hoped for – not yet, anyway. DOGE has fallen well short of the cuts it originally promised.

Daily Brief Summary

CYBERCRIME // Ransomware Group Mocks US Department Using Elon Musk's Tactics

Fog ransomware group incorporates satirical Elon Musk policy reference in updated ransom demands, demanding victims list their weekly accomplishments.

The ransom note mimics a policy from Musk’s tenure as head of the US Department of Government Efficiency (DOGE), where federal employees must submit five-point recaps of their weekly achievements.

The unusual demand in ransom notes reflects a trend of cybercriminals merging political satire with their illegal activities, possibly to mock victims and government inefficiencies.

Fog ransomware, active for about a year, targets both Windows and Linux systems across multiple industries, but little is known about its origins or group composition.

Trend Micro researchers have provided indicators of compromise and methods to defend against the Fog ransomware, highlighting the need for increased vigilance and protective measures.

Speculation surrounds Elon Musk’s future with the US government, with reports suggesting Musk may resign from DOGE by May due to frustrations with political opposition.

DOGE, under Musk’s guidance, aimed to drastically reform federal operations but has not reached its expected efficacy and budget-cutting goals.