AvosLocker is a ransomware-as-a-service operation identified in 2021. Initially focused on Windows business environments, it later introduced Linux encryptors designed to target VMware ESXi hosts and VMFS-backed virtual-machine infrastructure. The operation encrypts victim data and uses double extortion, exfiltrating data before encryption and threatening publication or sale of stolen material through leak-site and auction mechanisms when victims do not pay. AvosLocker has targeted organizations across multiple countries, including organizations in Europe, the Middle East, and North America.
AvosLocker affiliates have obtained access through phishing campaigns, weak remote-desktop credentials, and exploitation of exposed Microsoft Exchange Server vulnerabilities associated with ProxyShell. Post-compromise activity attributed to affiliates includes credential dumping, Active Directory and network discovery, remote execution and lateral movement, disabling endpoint defenses, deletion of recovery artifacts, and data exfiltration. AvosLocker has also been associated with Safe Mode boot abuse to impair endpoint security tooling.
Windows variants use multithreaded encryption and may enumerate local and network resources while applying file and directory exclusion logic. Linux variants are command-line ELF executables that support configurable encryption threads, identify ESXi and VMFS environments, terminate running virtual machines before encryption, and encrypt files across the specified target path. The operation uses an affiliate model and provides victim negotiation and decryption support.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Cyble Research Labs found through dark/deepweb research that the Threats Actors (TAs) or affiliates of AvosLocker ransomware groups are using Proxyshell to exploit Microsoft Exchange Server vulnerabilities compromising victim’s network, such as CVE-2021-34473, CVE-2021-31206, CVE-2021-34523, and CVE-2021-31207. | AvosLocker is a ransomware group identified in 2021, specifically targeting Windows machines... a new Linux variant of AvosLocker ransomware targeting VMware ESXi servers.
the following three ransomware families are being observed in the majority of recent attacks: Similar to many other ransomware families, Hive, Conti, and Avoslocker follow the ransomware-as-a-service (RaaS) business model.
the following three ransomware families are being observed in the majority of recent attacks: Similar to many other ransomware families, Hive, Conti, and Avoslocker follow the ransomware-as-a-service (RaaS) business model.
Cyble Research Labs found through dark/deepweb research that the Threats Actors (TAs) or affiliates of AvosLocker ransomware groups are using Proxyshell to exploit Microsoft Exchange Server vulnerabilities compromising victim’s network, such as CVE-2021-34473, CVE-2021-31206, CVE-2021-34523, and CVE-2021-31207. | AvosLocker is a ransomware group identified in 2021, specifically targeting Windows machines... a new Linux variant of AvosLocker ransomware targeting VMware ESXi servers.
the following three ransomware families are being observed in the majority of recent attacks: Similar to many other ransomware families, Hive, Conti, and Avoslocker follow the ransomware-as-a-service (RaaS) business model.
the following three ransomware families are being observed in the majority of recent attacks: Similar to many other ransomware families, Hive, Conti, and Avoslocker follow the ransomware-as-a-service (RaaS) business model.
Cyble Research Labs found through dark/deepweb research that the Threats Actors (TAs) or affiliates of AvosLocker ransomware groups are using Proxyshell to exploit Microsoft Exchange Server vulnerabilities compromising victim’s network, such as CVE-2021-34473, CVE-2021-31206, CVE-2021-34523, and CVE-2021-31207. | AvosLocker is a ransomware group identified in 2021, specifically targeting Windows machines... a new Linux variant of AvosLocker ransomware targeting VMware ESXi servers.
the following three ransomware families are being observed in the majority of recent attacks: Similar to many other ransomware families, Hive, Conti, and Avoslocker follow the ransomware-as-a-service (RaaS) business model.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
AvosLocker is a ransomware group that was identified in 2021, specifically targeting Windows machines. Now a new variant of AvosLocker malware is also targeting Linux environments.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Может распространяться путём взлома через незащищенную конфигурацию RDP, с помощью email-спама и вредоносных вложений, обманных загрузок, ботнетов, эксплойтов, вредоносной рекламы, веб-инжектов, фальшивых обновлений
Эти сценарии изменяют или удаляют ключи реестра, принадлежащие определенным инструментам безопасности конечных точек
Examples include AppleSeed using HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce, AvosLocker executed via the RunOnce Registry key, NanoCore creating a RunOnce key, and the content listing HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce and RunOnceEx paths. | Numerous malware families and threat groups are described as achieving persistence by adding values under Run/RunOnce/Policies\Explorer\Run Registry keys or by placing shortcuts/files in the Windows Startup folder.
Examples include AppleSeed using HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce, AvosLocker executed via the RunOnce Registry key, NanoCore creating a RunOnce key, and the content listing HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce and RunOnceEx paths. | Numerous malware families and threat groups are described as achieving persistence by adding values under Run/RunOnce/Policies\Explorer\Run Registry keys or by placing shortcuts/files in the Windows Startup folder.
Most of the strings in the malware are kept in the XOR encrypted format. The decryption routines are similar, only registers and keys are different. Strings are decrypted just before their use.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The modus operandi this ransomware group starts with data encryption and moves on to adding its own extension “GET_YOUR_FILES_BACK.txt” to each of the folders having these encrypted files.
After execution, the AvosLocker checks the presence of VMware ... and kills the Virtual Machines (VMs) if they are running
48 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family mentioned as another prior example of abusing Safe Mode to weaken endpoint defenses before encryption.
Referenced as another ransomware family known for using Safe Mode tactics to impair defenses.
Referenced as another ransomware family known for using Safe Mode tactics to impair security tools prior to ransomware execution.
Referenced as an older ransomware family associated with Safe Mode reboot tactics to evade security tooling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.