“RIDDLE SPIDER: the Avaddon ransomware operators, whose affiliates use SystemBC as a post exploitation tool.”
Avaddon
Avaddon is a Windows ransomware family operated through a ransomware-as-a-service affiliate program that recruited participants from mid-2020.
Avaddon
Family profile
Avaddon is a Windows ransomware family operated through a ransomware-as-a-service affiliate program that recruited participants from mid-2020. It affected organizations worldwide, including in Latin America. Its operators are tracked as RIDDLE SPIDER, and affiliates have used SystemBC for post-exploitation activity. Distribution included Phorpiex-delivered malicious archives, phishing emails containing malicious JavaScript attachments, and macro-enabled Excel documents. Affiliates also obtained access through weak credentials on RDP and VPN services.
Developed in C++, Avaddon encrypts files on local disks and network drives using AES-256 and RSA-2048, prioritizes database files, and changes encrypted-file extensions. It enumerates running processes, shared folders, and mapped volumes, and can determine a victim's external IP address. It terminates processes that could interfere with encryption, deletes backups and volume shadow copies, and empties the Windows Recycle Bin. Avaddon establishes persistence through scheduled tasks or Registry autorun entries and bypasses User Account Control using the CMSTPLUA COM interface. Anti-analysis features include virtual-machine checks, debugger detection, and encrypted strings. Language and regional checks prevent execution on selected systems associated with Commonwealth of Independent States countries, particularly Russian-language systems.
The operation combined file encryption with threats to publish stolen victim data through a leak site and began using DDoS attacks as additional extortion pressure in January 2021. These pressure tactics were operational services rather than established capabilities of the ransomware executable. Avaddon shut down on June 11, 2021, releasing 2,934 decryption keys that Emsisoft and Coveware validated and used to support free victim recovery.
Capabilities
- Ddos
- Defense Evasion
- Extortion
- Persistence
- Privilege Escalation
- Reconnaissance
Samples
Recent samples
6 sandbox samples in the Derp library, newest 6 shown
b7569f418ec00edc2f2cc982702fefaf90e4fd677f3b6bded7b5228409bb999b ef2cf80f858aeb25d860453377a9d79cb4d8996e75782ac90e2aa0b217f09487 04db39659104b1a6b6a96f7ae7d65d977d34b14cbfa4372de843e757590b901f 2b0b0721b689615a24dbd8588f9c2ca179229b878915e0ed60b3803e6d75c6f1 3446535b78036d1d6ecb2e5d859c4b28739e2811f1b5ceb98976cdc1909ec0c9 0ab32563d41497bb417471f4b2059c73a611b9d4efdf67d7d2352e1828f25f4f Reported operators
Threat actors
2 named in public reportingBassterlord, a suspected Russian-speaking threat actor who previously served as an affiliate for the LockBit ransomware gang, but also other rival RaaS operations, such as REvil, Avaddon, and RansomExx.
Exploited software
Vulnerabilities linked to Avaddon
1 CVEsMITRE ATT&CK
Avaddon in ATT&CK
58 distinct techniquesTechniques
58 techniquesReporting
Research mentioning Avaddon
Post by @lazarusholic.bsky.social - Bluesky
A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.
Detection: Windows Suspicious Child Process of Consent.EXE | Splunk Security Content
Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.
Windows Suspicious Child Of Consent.exe | Splunk Security Content
Telegram shortlinks knocked offline over sanctioned VPN connection
The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.