Avaddon was a Russian-speaking ransomware-as-a-service operation active from late 2019 until June 2021. It emerged as a major big-game hunting ransomware threat, recruiting affiliates on prominent Russian-language cybercrime forums and operating a mature affiliate model with an automated leak portal. The group conducted double extortion by encrypting victim systems and threatening to publish stolen data, and later adopted additional pressure tactics including distributed denial-of-service attacks, making it part of the broader shift toward triple-extortion ransomware. Avaddon initially spread through phishing campaigns using malicious attachments and later also leveraged weak credentials on remote access services such as RDP and VPN appliances for initial access. Its malware, developed in C++, used anti-analysis measures including anti-VM and anti-debugging checks, attempted privilege escalation via a UAC bypass, established persistence through scheduled tasks or Run-key autoruns, terminated processes that could interfere with encryption, deleted backups and shadow copies, and encrypted files across local and network-accessible storage using AES-256 and RSA-2048. The malware also avoided execution on systems configured for CIS-region languages, especially Russian, a common trait among post-Soviet cybercriminal ransomware. The operation maintained a data leak site to extort non-paying victims and publicly advertised or supported affiliate activity until pressure on the ransomware ecosystem increased after the Colonial Pipeline incident. Following that disruption, Avaddon announced it would move to private operations with selected affiliates and stated that attacks on government, healthcare, and education entities were prohibited. In June 2021, Avaddon abruptly shut down, wiped its public presence, and released thousands of decryption keys that enabled recovery for past victims. Security researchers have noted the possibility of rebranding after the shutdown, but only the shutdown and key release are firmly established. Avaddon has also been referenced as an influence on later ransomware variants, including families reported to share similarities with Avaddon and Thanos-derived tooling.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
60 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
24 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in a list of ransomware groups known for affiliate programs and leak blogs.
Referenced as one of the ransomware groups that used First VPN infrastructure for network reconnaissance and intrusions.
Referenced only for comparison, as Haron showed similarities to Avaddon in ransom note and leak site characteristics.
Mentioned as adopting triple extortion tactics after SunCrypt and RagnarLocker.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.