NoEscape is a financially motivated ransomware-as-a-service (RaaS) operation that emerged in May 2023 and is widely assessed to be a rebrand or spin-off of Avaddon. The group conducts extortion through encryption and theft of victim data, operating a leak site to pressure non-paying organizations and offering affiliates tooling for both Windows and Linux payload generation. Reporting also indicates NoEscape promoted additional coercive options such as DDoS or spam-based pressure, consistent with multi-extortion tradecraft. NoEscape activity has been associated primarily with targets in the United States, with manufacturing, education, construction, and other enterprise environments among affected sectors. Public victim reporting and incident investigations also show compromises involving government-related entities, healthcare-related organizations, and cloud-oriented targets. The operation has been linked to attacks against universities and cross-border public bodies, and victimology indicates broad opportunistic targeting typical of profit-driven RaaS programs rather than a narrow strategic mission. Operationally, NoEscape affiliates have gained access through phishing, malicious downloads, exploitation of public-facing Microsoft Exchange vulnerabilities such as ProxyShell, and likely purchased access from initial access brokers. Post-compromise behavior includes credential dumping, use of valid accounts, lateral movement via RDP, stealthy command execution through WMI and COM, persistence through scheduled tasks, and exfiltration to cloud storage. Incident reporting also shows use of remote administration software and SSH tunneling to maintain access. The malware and associated intrusions demonstrate mature defense-evasion and impact capabilities. Observed behaviors include anti-debugging checks, avoidance of CIS-language systems, attempts to weaken endpoint protections, deletion of shadow copies and backups, stopping services and processes that could interfere with encryption, and clearing Windows event logs. Technical analyses describe host discovery, process termination via Restart Manager APIs, UAC tampering, mutex-based execution control, and hybrid cryptographic workflows using embedded configuration data and public-key protection of generated encryption material. NoEscape has been described as avoiding victims in CIS or former Soviet states, a pattern commonly associated with Russian-speaking ransomware ecosystems. The operation has also appeared in affiliate-recruitment and ecosystem reporting alongside other major RaaS brands, and later suffered allegations of an exit scam and loss of affiliate trust after its leak site went offline. Separate government reporting has noted that Iranian actors have worked as affiliates with Russian ransomware gangs including NoEscape, but that does not change NoEscape’s characterization as a criminal RaaS operation rooted in the Russian-speaking cybercrime milieu.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a distinct RaaS program advertised on RAMP.
Claimed responsibility for a prior ransomware-related breach of the University of Hawaii, alleging theft of 65GB of sensitive data.
Ransomware operation referenced as having affiliates that partnered with Iranian actors in profit-sharing arrangements.
Unconfirmed association with suspicious activity involving the Powerhouse domain in late 2023; not publicly attributed as the confirmed actor behind the 2026-disclosed breach.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.