Avaddon was a Windows ransomware family and ransomware-as-a-service operation active from late 2019 through June 2021. It recruited affiliates from 2020 and targeted organizations globally, including organizations in Latin America. Initial access and distribution included phishing emails carrying malicious attachments, including script-based attachments and macro-enabled documents; affiliates also abused weak credentials protecting remote-access services such as RDP and VPNs. Phorpiex campaigns distributed Avaddon during 2020 and early 2021. Avaddon combined file encryption with data-theft extortion and maintained a leak site for publishing victim data. The operators also claimed to use DDoS attacks to pressure victims.
Written in C++, Avaddon searched local disks, mapped volumes, and network shares, with emphasis on database files. It encrypted files using AES-256 and RSA-2048, applied randomized extensions, terminated processes that might impede encryption, and deleted backups and shadow copies. It performed process and network discovery, including collection of the external IP address. The malware used anti-debugging and anti-virtualization checks, encrypted strings, Windows Registry Run-key and scheduled-task persistence, and a CMSTPLUA COM-based UAC bypass. It avoided executing on systems configured with CIS-region languages, particularly Russian. The operation ceased in June 2021; its operators released decryption keys later validated by Emsisoft and Coveware, enabling recovery for affected victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The security researcher noted that all the Pulse Secure VPN servers included in the list were running a firmware version vulnerable to the CVE-2019-11510 vulnerability. Bank Security believes that the hacker who compiled this list scanned the entire internet IPv4 address space for Pulse Secure VPN servers, used an exploit for the CVE-2019-11510 vulnerability to gain access to systems, dump server details (including usernames and passwords), and then collected all the information in one central repository.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“RIDDLE SPIDER: the Avaddon ransomware operators, whose affiliates use SystemBC as a post exploitation tool.”
Bassterlord, a suspected Russian-speaking threat actor who previously served as an affiliate for the LockBit ransomware gang, but also other rival RaaS operations, such as REvil, Avaddon, and RansomExx.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
más adelante hacer uso de credenciales de acceso débiles en servicios de acceso remoto, como RDP y redes VPN
El código JScript a su vez ejecuta comandos de Powershell para descargar el ransomware de un servidor web
también se ha visto utilizar en sus comienzos archivos Excel con macros maliciosas
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
After the attachment is downloaded and ran, it uses a PowerShell command and the BITSAdmin command-line tool to download and run the ransomware payload.
incluyen un archivo JScript malicioso adjunto... para hacerle creer a la potencial víctima que se trata de un archivo comprimido que contiene una foto comprometedora
Avaddon bypasses UAC using the CMSTPLUA COM interface... LockBit 3.0 can bypass UAC to execute code with elevated privileges through an elevated Component Object Model (COM) interface. Medusa Group has attempted to bypass UAC using Component Object Model (COM) interface.
más adelante hacer uso de credenciales de acceso débiles en servicios de acceso remoto, como RDP y redes VPN
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
After the attachment is downloaded and ran, it uses a PowerShell command and the BITSAdmin command-line tool to download and run the ransomware payload.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
más adelante hacer uso de credenciales de acceso débiles en servicios de acceso remoto, como RDP y redes VPN
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
As the bot loader updates, the key values change to reflect new files, randomized file paths, and masqueraded system files. The example below illustrates a change from SVCHOST to LSASS
más adelante hacer uso de credenciales de acceso débiles en servicios de acceso remoto, como RDP y redes VPN
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
APT1 listed connected network shares. APT32 used the net view command to show all shares available, including the administrative shares such as C$ and ADMIN$. APT41 used the net share command as part of network reconnaissance.
The criminal group behind the Avaddon ransomware has shut down its operation today and released decryption keys for past victims. | The decryptor will take the 2,934 decryption keys and allow past Avaddon victims to decrypt their files for free if they still have the encrypted files around and have not deleted the data.
63 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
95 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as ransomware historically associated with RIDDLE SPIDER affiliates that use SystemBC.
Mentioned in a list of ransomware operations known for affiliate programs and leak blogs.
A named ransomware family cited as one of the groups that used the sanctioned VPN service 1VPNS for reconnaissance and intrusions.
Named ransomware group/family cited as one of the users of First VPN infrastructure for reconnaissance, initial access, data theft, and other attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.