Avaddon emerged as a ransomware-as-a-service operation that initially spread through a massive phishing campaign using smiley-themed lures such as “Your new photo?” and JavaScript attachments disguised as images. The malware downloaded its payload with PowerShell and BITSAdmin, encrypted files with the .avdn extension, dropped HTML ransom notes, changed desktop wallpaper, and directed victims to Tor-based payment pages. Researchers and vendors linked early distribution to large botnet-driven spam activity and later observed affiliates using additional access methods including exposed RDP, weak VPN credentials, and network vulnerability exploitation.
As the operation matured, Avaddon expanded into multi-extortion, publicly listing victims on a leak site, releasing stolen data, and in some cases adding DDoS pressure while continuously updating its code to evade detection and defeat public decryptors. Reports described anti-analysis features, persistence via scheduled tasks and Run registry keys, deletion of backups and shadow copies, and regional exclusions that avoided CIS-language systems. After becoming one of the most active ransomware threats and drawing warnings from authorities, the group abruptly shut down and released 2,934 decryption keys, which were validated by incident-response firms and used to build a free decryptor for victims.

TTPs, infrastructure, and targeting history in one profile.
16 events from the most recent confirmed update back to the earliest known activity.
After receiving the keys via BleepingComputer, Emsisoft prepared a free decryptor for Avaddon victims, and the keys were validated by Emsisoft and Coveware.
On June 11, 2021, the Avaddon ransomware operation shut down, took its servers and leak site offline, and released 2,934 decryption keys for past victims.
In May 2021, the Australian Cyber Security Centre reported that Avaddon operators demanded an average ransom of 0.73 bitcoin, about $40,000.
At the start of May 2021, both the FBI and the Australian Cyber Security Centre issued alerts about Avaddon's growing number of intrusions.
SentinelOne says Avaddon added Monero as a payment option in February 2021, broadening the cryptocurrency choices available to victims.
Shortly after the Colonial Pipeline attack, Avaddon announced plans to go private and work only with a selected number of affiliates, according to The Record.
After the public decryptors appeared in early 2021, Avaddon changed its encryption model to invalidate them and temporarily raised the affiliate revenue share to 80% for one month as compensation.
In early 2021, Bitdefender released a public decryptor for Avaddon and researcher Javier Yuste published an open-source decryptor, with the tool also distributed through NoMoreRansom.org.
SentinelOne reports that Avaddon added DDoS attacks as an intimidation mechanism in January 2021, extending its pressure tactics beyond encryption and data leaks.
In January 2021, Avaddon expanded compatibility to Windows XP and Windows Server 2003, according to SentinelOne's retrospective analysis.
SentinelOne states that Avaddon added round-the-clock affiliate support via chat and ticketing in August 2020, reflecting maturation of its ransomware-as-a-service operation.
By July 2020, Trend Micro reported Avaddon as a newly observed ransomware family spreading through JavaScript-in-ZIP email attachments, using PowerShell and BITSAdmin to fetch its payload and encrypt files with the .avdn extension.
SentinelOne reports that Avaddon added PowerShell payload-launch capability in late June 2020 as part of its ongoing feature development for affiliates.
Avaddon was distributed in a large-scale phishing/spam campaign using photo-themed lures and ZIP archives containing JavaScript downloaders disguised as JPG files. AppRiver attributed the distribution to the Phorpiex/Trik botnet and reported blocking more than 300,000 malicious emails in a short period.
At the beginning of June 2020, Avaddon emerged publicly as a ransomware-as-a-service/affiliate operation promoted on Russian-speaking underground forums, with rules excluding CIS-country targets and revenue sharing for affiliates.
SentinelOne says Avaddon ransomware was first observed in the wild in February 2020, marking the earliest explicit sighting in the provided references.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 58 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
labs.sentinelone.com
Open sourcetherecord.media
Open sourceemsisoft.com
Open sourcewelivesecurity.com
Open sourcetrendmicro.com
Open sourcebleepingcomputer.com
Open sourceblog.trendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.