Fog Ransomware Gang is Scanning Small Manufacturers for Exposed RDP Ports Right Now
The FBI just dropped a fresh alert because the Fog ransomware group is actively hunting small manufacturers and industrial service companies with open remote desktop ports.
What Happened
Fog is hitting shops with exposed RDP, the same remote access tool a lot of teams use to work from anywhere. They’ve already taken down at least 47 small manufacturers in May alone. Once they get in they grab the data, lock everything up, and try to sell what they stole.
This is not some random spike. The group made a deliberate shift toward companies with under 100 employees. Those shops usually have less IT watching the doors, which makes them lower-risk targets for the attackers.
Albert has seen what this looks like up close. One of the worst ransomware hits he dealt with came from a customer who left remote access wide open and paid for it later.
What This Means for Your Business
The villain here is exposed RDP combined with the assumption that small shops are too small to bother with. When that door stays open, you end up reacting after the fact while your data gets stolen and sold, especially if any of your work touches defense contracts.
Most owners do not find out until the files are already encrypted and the demands start coming in. That is the exact spot the Fog group is counting on.
What To Do This Week
- Check every machine that uses remote desktop and close the port if it is not needed.
- If your team must use RDP, put it behind a VPN and turn on multi-factor authentication today.
- Run a quick scan of your public IP addresses to see which ports are actually visible from outside.
- Make a list of every vendor or employee who has remote access and remove anyone who no longer needs it.
Questions about how this affects your setup? Schedule a free IT consultation and we’ll walk through it with you.