Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
1 malware family

NoEscape

Also known asnoescape

NoEscape is a financially motivated ransomware-as-a-service (RaaS) operation first observed in May 2023 and widely reported as a rebrand or spin-off of Avaddon. It uses double extortion, combining data theft with file encryption, and some reporting notes additional extortion options such as DDoS/spam and call-center support. The group is described as avoiding targets in the former Soviet Union. Within seven months, NoEscape reportedly listed 145 compromised organizations on its leak site, and one source attributed 4.4% of observed incidents (9 incidents) to the group. Observed delivery and intrusion methods in the provided content include malicious file downloads and infected email attachments, exploitation of public-facing Microsoft Exchange ProxyShell vulnerabilities (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) leading to webshell deployment, use of PowerShell to add Microsoft Defender exclusions, credential dumping from LSASS, and lateral movement primarily via RDP using valid domain credentials. Additional reported tooling and techniques include Plink to tunnel RDP over SSH, TeamViewer for access, MegaSync for exfiltration to Mega, scheduled-task execution via "SystemUpdate," and in another case use of NPPSPY to capture cleartext Exchange credentials, followed by RDP-based lateral movement and likely data exfiltration. One forensic account specifically states NoEscape performed lateral movement via RDP with a domain admin account. Victims and claimed victims mentioned in the content include the University of Hawaii, where NoEscape claimed in June 2023 to have stolen 65GB of sensitive data; the International Joint Commission, which NoEscape listed on September 7 and claimed to have stolen 80GB of data from; Italian technical consultancy Kreacta; Lithuania’s Republican Vilnius Psychiatric Hospital; Taiwanese manufacturer Avertronics; and an October 2023 incident referenced in relation to the Order of Psychologists of the Lombardy Region. The content also notes unconfirmed monitoring linking NoEscape activity to powerhousenow.com in late 2023. The group’s ecosystem relationships in the content include LockBitSupp encouraging NoEscape and ALPHV affiliates in late 2023 to use the LockBit leak site after disruption to rival groups. The content also states Iranian threat actors have been observed working as affiliates with Russian ransomware gangs including NoEscape, RansomHouse, and ALPHV, and that the FBI observed Iranian actors partnering with affiliates of NoEscape and taking a percentage of ransom payments. Separately, Prodaft reporting cited in the content says Mikhail Matveev (Wazawaka) worked as an affiliate of NoEscape. The content indicates NoEscape’s operations degraded in late 2023: it had not reported new victims after December 4, 2023, affiliates allegedly accused the operators of an exit scam involving ransom payments worth millions, and the group reportedly took down its leak site and lost affiliate trust. Known alias in the provided content: Avaddon (reported rebrand/spin-off relationship).

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

6 of 15 tactics11 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1566
Phishing
T1566.001
Spearphishing Attachment
TA0002
Execution
1 technique
T1204
User Execution
T1204.002
Malicious File
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.001
Remote Desktop Protocol
TA0009
Collection
1 technique
T1213
Data from Information Repositories
TA0010
Exfiltration
1 technique
T1041
Exfiltration Over C2 Channel
TA0040
Impact
3 techniques
T1486×2
Data Encrypted for Impact
T1490
Inhibit System Recovery
T1657
Financial Theft
ARSENAL

Associated malware families

1 malware family attributed to this actor across reporting.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping9

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.