AvosLocker is a ransomware-as-a-service (RaaS) operation that emerged in 2021 and is known for double-extortion attacks combining data theft with file encryption and leak-site pressure. The group has targeted critical infrastructure and other organizations in multiple Western countries, with confirmed victim geography including the United States, Canada, the United Kingdom, and Spain. AvosLocker has also been advertised on Russian-language cybercrime forums and has been listed among active RaaS programs in that ecosystem. AvosLocker intrusion activity has been associated with several common initial-access vectors, including spear-phishing, exploitation of public-facing applications, and use of compromised Remote Desktop Protocol credentials. Post-compromise behavior includes deployment of custom web shells for persistence, credential dumping for privilege escalation, data exfiltration prior to encryption, and abuse of remote access and administration tooling. Reporting also links the group to use of legitimate tools and services frequently seen in ransomware operations, including FileZilla for exfiltration support and RDP for remote access and lateral movement. AvosLocker has also been associated with abuse of legitimate or vulnerable drivers and security-tool-disabling capabilities used to bypass defensive controls. The operation has been reported to reboot systems into Safe Mode with Networking before encryption in order to reduce interference from security products. AvosLocker has also been identified among ransomware families targeting VMware ESXi environments. The group is widely discussed alongside other post-Conti ransomware ecosystems, and some reporting has placed AvosLocker among the operations that absorbed former Conti personnel or affiliates after Conti’s fragmentation. High-confidence reporting supports AvosLocker as a financially motivated cybercriminal enterprise rather than a state-sponsored actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RaaS operation advertising on RAMP and directly seeking to buy or work corporate access such as VPN-to-RDP, Citrix, and webshell access.
Referenced as a ransomware group that some former Conti members allegedly joined after Conti’s retirement; described here as no longer active.
Named as a ransomware operation that former Conti members allegedly infiltrated or took over.
Referenced as a ransomware group reported to have obtained/used FIN7’s AvNeutralizer EDR-disabling tool.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.