Fog ransomware channels Musk with demands for work recaps or a trillion bucks
- Reference: 1745344933
- News link: https://www.theregister.co.uk/2025/04/22/fog_ransomware_musk/
- Source link:
Victims not only have to cough up cash to feed the crime machine, but according to researchers, they're being trolled with the DOGE chief's infamous five-bullet-point demand to know what federal workers achieved that week.
"Give me five bullet points on what you accomplished for work last week or you owe me a trillion dollars," a new line to Fog's updated ransom note reads.
[1]
It refers to one of Musk's earliest policies after he was installed as the head of the US Department of Government Efficiency (DOGE), one that has been consistently applied across all of his companies.
[2]
[3]
A memo was dispatched to workers demanding they outline five accomplishments from their past workweek in a bid to meet President Trump's request that federal staff be treated more aggressively.
Following immediate pushback, other department heads made the controversial demand optional.
[4]
According to the [5]Washington Post , insiders expressed privacy concerns about the emails but were also worried they would lose their jobs if they didn't respond.
As for why Fog decided to reference it in its new ransom note, Trend's researchers believe it's a sign of the criminals poking fun at victims and their sitting government.
Other iterations of the note, which list several DOGE staffers, could also be seen as a reference to recent reports linking Edward Coristine – whose current role at DOGE is unknown – to the provision of tech support to a cybercrime gang.
[6]
Reuters [7]reported last month that Coristine, whose online handle is "bigballs," previously ran a company called DiamondCDN before joining DOGE, which was linked to the alleged provision of DDoS protection services to dataleak.fun – a site run by the now dormant EGodly group.
[8]Guess what happens when ransomware fiends find 'insurance' 'policy' in your files
[9]Now 1.6M people had SSNs, life chapter and verse stolen from insurance IT biz
[10]Ransomware crims hammering UK more than ever as British techies complain the board just doesn't get it
[11]US sensor giant Sensata admits ransomware derailed ops
Trend's researchers said it could have been Fog itself or another group using Fog's binaries, but in any case, they've [12]dropped some useful intel and indicators of compromise on how to stop the ransomware.
Fog hasn't been on the scene for too long – around a year – and not much is known about its makeup or origin, only that it targets Windows and Linux systems across various industries.
Meanwhile, Musk's political career is also up in the air as speculation mounts about his role in the US government. The Washington Post reported this week that Musk may exit as soon as May, with the move believed to be driven by the billionaire's growing frustration with political attacks from the left.
The plan is to still keep DOGE running and it is seen internally as an organization that shows how swiftly government departments can be radically overhauled, where necessary.
But it isn't the success story many had hoped for – not yet, anyway. DOGE [13]has fallen well short of the cuts it originally promised . ®
Get our [14]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aAgRjR3ezlDjyunEIgjnsQAAAAM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aAgRjR3ezlDjyunEIgjnsQAAAAM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aAgRjR3ezlDjyunEIgjnsQAAAAM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aAgRjR3ezlDjyunEIgjnsQAAAAM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://www.washingtonpost.com/politics/2025/04/21/doge-musk-trump-federal-employees-emails/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aAgRjR3ezlDjyunEIgjnsQAAAAM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.reuters.com/world/us/doge-staffer-big-balls-provided-tech-support-cybercrime-ring-records-show-2025-03-26/
[8] https://www.theregister.com/2025/04/16/dutch_ransomware_study/
[9] https://www.theregister.com/2025/04/15/landmark_admin_data_loss/
[10] https://www.theregister.com/2025/04/11/uk_cyberattacks/
[11] https://www.theregister.com/2025/04/10/us_sensor_giant_sensata_ransomware/
[12] https://www.trendmicro.com/en_us/research/25/d/fog-ransomware-concealed-within-binary-loaders-linking-themselve.html
[13] https://www.theregister.com/2025/04/20/musks_doge_promises_fail/
[14] https://whitepapers.theregister.com/
Hey! That was my day at work too!
But loading/unloading the communal dishwasher, that shows we're oldsters. Young people of today, etc etc.
Well I , oh, hang on I don't have to say because I don't work for you.
OTOH loading and unloading the communal dishwasher, whoa! That is above and beyond.
Take a bow.
(Smiley 'smug git' icon.)
130 Days time limit
Musk is a 'special government employee', and that comes with a time limit of 130 days, then his employment will terminate.
"If it’s really the case that Musk is a mere adviser operating as a special government employee, then he can only stay in that job until May 30, and would have to vacate the White House after that. Most of his DOGE teams, also serving as SGEs, would have to leave too.
...
The “special government employee” designation was intended for members of advisory commissions, who it was thought shouldn’t have to go through cumbersome ethics pledges and financial disclosures to serve on a board and offer advice. As a result, the law was shaped so permanent employees couldn’t serve as SGEs. The federal code is quite clear: An SGE’s term is “not to exceed one hundred and thirty days during any period of three hundred and sixty-five consecutive days.” Ethics rules state that this is based on a “good faith estimate” of how long the government service will take, and that estimate must be made in advance. Any work done on a day is counted as a workday."
https://prospect.org/politics/2025-02-19-elon-musk-only-has-100-days-left-in-government/
If this is the case, then the would account for the haste with which DOGE staff pursued their tasks. But it will be interesting to see what happens at the end of next month.
Re: 130 Days time limit
Since when has Trump ever respected any rule he couldn't bend in his favor ?
You owe me a trillion dollars
If Trump sacks Powell that could be little more than small change for most of us. So, top trolling!
Oh dear.
...the billionaire's growing frustration with political attacks from the left.
"If you can't stand the heat, get out of the kitchen".
Harry S. Truman
Could not have put it better.
People with thin skins should stay out of politics, it's a rough game.
Re: Oh dear.
The political issue with a 'thin skin' for a politician is that as every criticism is treated as a personal and unfair attack, when someone does present a genuine problem that actually needs attention and should be dealt with properly, it is treated the same, as an intrusive personal attack not worthy of anything other than a rejection. Boris Johnson was like that when Mayor of London, MP and as PM. He simply did not comprehend that anyone could possibly have a valid criticism of his actions or policies.
Oh, and treating politics as a game, when people's lives literally depend on what you do is, wrong, very, very wrong.
Re: Oh dear.
...the billionaire's growing frustration with political attacks from the left.
Oh dear, what a pity, how sad.
Moving on.....
1. I showed up at work.
2. I booted my computer.
3. Whit is was busy booting I cleared and refilled the dish washer (we have one or two for each floor, the people are responsible to use them).
4. I opened Outlook.
5. I opened Teams.
Now give my the treeeelllllion bucks!