Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareRansomwareUsed by 1 actorExploits 3 CVEs

NoEscape

NoEscape is a ransomware-as-a-service (RaaS) operation first observed being advertised on a dark web forum in May 2023. Reporting in the provided content describes it as financially motivated, using double extortion through file encryption and data exfiltration, with additional extortion options including DDoS/spam services and call-center support. Multiple sources in the content state NoEscape is believed to be a spin-off or rebrand of the former Avaddon ransomware group.

Observed tradecraft includes exploitation of public-facing Microsoft Exchange servers via ProxyShell vulnerabilities (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), webshell deployment, PowerShell-based Microsoft Defender exclusions, credential dumping from LSASS, and lateral movement primarily via RDP using valid domain credentials. In one NCC Group case, operators also tunneled RDP over SSH using PuTTY Link (Plink) to 172.93.181[.]238, leveraged existing TeamViewer access, exfiltrated data with MegaSync.exe to Mega cloud storage, and executed the encryptor via a scheduled task named "SystemUpdate." The content also describes a separate NGO intrusion in which NoEscape operators allegedly purchased previously established access to an unpatched on-premises Exchange environment, used the NPPSPY credential-theft technique via a malicious network provider DLL, installed AnyDesk for persistence, performed enumeration with Nmap/Zenmap and PowerView, and likely exfiltrated data to Mega. The ransomware encryptor was reported to target files on the C:\ drive while excluding numerous extensions.

The content links NoEscape to victim extortion and public leak-site activity. It states the victim portal reportedly listed 89 victims at the time of one report, with the first victim posted on 14 June 2023. Mentioned incidents include a June 2023 claim by NoEscape that it breached the University of Hawaii and stole 65 GB of sensitive data, and reporting tying NoEscape to an October 2023 attack involving the Order of Psychologists of the Lombardy Region, where data was allegedly exfiltrated and later published after ransom non-payment.

NoEscape appears in broader ransomware ecosystem reporting as one of the RaaS programs advertised on the RAMP cybercrime forum. The content also notes overlap between ransomware ecosystems: LockBitSupp encouraged ALPHV/BlackCat and NoEscape affiliates to use the LockBit leak site in late 2023, and Mikhail Matveev was reported to have worked as an affiliate for NoEscape in addition to several other ransomware groups. Separately, FBI reporting cited in the content states Iranian actors partnered with affiliates of NoEscape, Ransomhouse, and ALPHV and took a percentage of ransom payments.

Known indicators and artifacts directly mentioned in the content include CVE-2021-34473, CVE-2021-34523, CVE-2021-31207 (ProxyShell); Mega-related IP 66.203.125[.]14; Plink remote endpoint 172.93.181[.]238; and a Meterpreter stager communicating with 103.112.232.44:443 in a case later attributed to NoEscape operators purchasing access.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

3 CVES
CVE-2021-34473ProxyShell Autodiscover SSRF in Microsoft Exchange Server

“This post will delve into a recent incident response engagement… involving the Ransomware-as-a-Service known as NoEscape.”

via ncc group researchnccgroup.com
CVE-2021-31207Post-auth Arbitrary File Write in Microsoft Exchange Server (ProxyShell)

“This post will delve into a recent incident response engagement… involving the Ransomware-as-a-Service known as NoEscape.”

via ncc group researchnccgroup.com
CVE-2021-34523Microsoft Exchange PowerShell Backend Elevation of Privilege (ProxyShell)

“This post will delve into a recent incident response engagement… involving the Ransomware-as-a-Service known as NoEscape.”

via ncc group researchnccgroup.com
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
NoEscape

“This post will delve into a recent incident response engagement… involving the Ransomware-as-a-Service known as NoEscape.”

via ncc group researchnccgroup.com
MITRE ATT&CK

Techniques & procedures

1 distinct technique documented for this family, organized by ATT&CK tactic.

Impact

1 technique
T1486Data Encrypted for ImpactEvidence2

The actors have partnered with affiliates of the NoEscape, Ransomhouse and AlphV ransomware operations ... In some cases the hackers have worked with ransomware gangs to “lock victim networks and strategize on approaches to extort victims.”

INDICATORS OF COMPROMISE

IOCs tracked for this family

1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app2 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching1

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities3

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping1

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.