AvosLocker is a ransomware family and Ransomware-as-a-Service operation that emerged in 2021 and has been associated with double-extortion intrusions in which data is stolen prior to encryption. It has targeted organizations including critical infrastructure entities in countries such as the United States, Canada, the United Kingdom, and Spain. Reported access vectors include spearphishing, exploitation of public-facing applications, and use of compromised Remote Desktop Protocol credentials.
AvosLocker is known for encrypting local files and network resources and for appending characteristic extensions to affected files. The malware has also been observed enumerating shared drives to expand encryption impact across accessible network resources. On Windows, it employs defense-evasion measures including hiding its console window through the ShowWindow API and using obfuscated API resolution via checksums. It has also been associated with Safe Mode boot abuse to impair endpoint protections during ransomware execution, and reporting has linked it to abuse of legitimate drivers to bypass anti-tampering protections through kernel-space access.
The family has Linux capability as well, including an ESXi-focused variant that terminates virtual machines before encryption to maximize impact on virtualized environments. AvosLocker has additionally been observed checking system time before and after encryption, consistent with execution control and operational tracking behaviors. Samples have been disguised as benign-looking files, including image files, as part of masquerading tradecraft.
AvosLocker has been advertised on criminal forums as a RaaS program and is regarded as part of the broader trend of enterprise-targeting ransomware operations that combine intrusion, data theft, defense impairment, and multi-platform encryption against Windows and Linux-based infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Across the content, malware repeatedly 'adds Registry Run keys', 'creates Registry entries', 'modifies the Windows Registry', or 'overwrites registry keys' to maintain persistence.
Examples include AppleSeed using HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce, AvosLocker executed via the RunOnce Registry key, NanoCore creating a RunOnce key, and the content listing HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce and RunOnceEx paths. | Numerous malware families and threat groups are described as achieving persistence by adding values under Run/RunOnce/Policies\Explorer\Run Registry keys or by placing shortcuts/files in the Windows Startup folder.
Additionally, adversaries may exploit legitimate drivers from anti-virus software to gain access to kernel space (i.e. Exploitation for Privilege Escalation), which may lead to bypassing anti-tampering features.
Examples include AppleSeed using HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce, AvosLocker executed via the RunOnce Registry key, NanoCore creating a RunOnce key, and the content listing HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce and RunOnceEx paths. | Numerous malware families and threat groups are described as achieving persistence by adding values under Run/RunOnce/Policies\Explorer\Run Registry keys or by placing shortcuts/files in the Windows Startup folder.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
During the 2016 Ukraine Electric Power Attack, Sandworm Team masqueraded executables as .txt files.
Kapeka masquerades as a Microsoft Word Add-In file, with the extension .wll, but is a malicious DLL file.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Multiple malware and threat groups are described as collecting/deriving local system time, date, timestamp, tick count, or time zone (e.g., "used time /t and net time \ip/hostname for system time discovery"; "collects the timestamp from the victim’s machine"; "can collect the time zone information from the system").
Since early 2023, AvNeutralizer has been used in numerous intrusions, including with the subsequent deployment of well-known ransomware strains such as AvosLocker, MedusaLocker, BlackCat, Trigona, and LockBit.
"AcidPour includes functionality to reboot the victim system following wiping actions..."; "AcidRain reboots the target system once the various wiping processes are complete"; "Apostle reboots the victim machine following wiping"; "APT37 ... issue the command shutdown /r /t 1 to reboot a system after wiping its MBR"; "APT38 ... BOOTWRECK ... initiate a system reboot after wiping the victim's MBR"; "Black Basta ... used ShellExecuteA to shut down and restart"; "DarkGate ... used the shutdown command"; "HermeticWiper can initiate a system shutdown"; "NotPetya will reboot the system one hour after infection"; "Shamoon will reboot the infected system once the wiping functionality has been completed"; "WhisperGate can shutdown ... through ... ExitWindowsEx"
Adversaries may modify and/or disable security tools to avoid possible detection of their malware/tools and activities.
This may take many forms, such as killing security software processes or services, modifying / deleting Registry keys or configuration files so that tools do not operate properly, or other methods to interfere with security tools scanning or reporting information.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a ransomware family known for abusing Safe Mode to disable security tools before encryption.
Referenced as an example of a ransomware family known to use Safe Mode boot to impair defenses.
A ransomware operation and RaaS program advertised on RAMP that also directly sought to buy corporate access.
Named ransomware group referenced as a destination for former Conti members; no additional technical details provided.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.