NoEscape was a financially motivated ransomware-as-a-service (RaaS) operation that emerged in May 2023. It is widely assessed as a rebrand or spin-off of Avaddon, although its operators claimed the ransomware was developed independently. The operation provided affiliates with configurable Windows and Linux payloads and used a leak site to support extortion. NoEscape is associated with Russian-speaking ransomware ecosystems and reportedly avoided targets in CIS countries. NoEscape conducted double-extortion operations, combining data theft with file encryption and threats to publish stolen material. Its affiliate offering also included DDoS and spam-based pressure options. From June through December 2023, the group publicly named more than 120 alleged victims, with the United States accounting for the largest identified share. Manufacturing, education, and construction were among the most affected sectors. The operation also made claims involving healthcare entities and government-related organizations, including the International Joint Commission; public leak-site claims should not be treated as confirmation of all asserted compromises. Observed NoEscape intrusions include exploitation of public-facing Microsoft Exchange ProxyShell vulnerabilities to deploy web shells; PowerShell-based Microsoft Defender exclusion changes; credential dumping; use of valid accounts for RDP-based lateral movement; SSH-tunneled RDP and remote-access software for persistence or backup access; and cloud-storage exfiltration. Operators and affiliates used scheduled tasks for persistence and ransomware execution, disabled or impaired endpoint defenses, deleted backups and shadow copies, stopped services and processes that could impede encryption, and cleared event logs. The ransomware incorporated anti-debugging and CIS-language checks, gathered host and drive information, and targeted Windows and VMware-related enterprise environments. In late 2023, affiliates alleged that NoEscape operators had conducted an exit scam involving ransom payments. The group stopped posting new victims and its leak site went offline around December 2023. LockBit subsequently attempted to recruit NoEscape affiliates and offered its own leak-site and negotiation infrastructure to facilitate continued extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a distinct RaaS program advertised on RAMP.
Claimed responsibility for a prior ransomware-related breach of the University of Hawaii, alleging theft of 65GB of sensitive data.
Ransomware operation referenced as having affiliates that partnered with Iranian actors in profit-sharing arrangements.
Associated with healthcare-sector dedicated leak-site postings.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.