Skip to content

Avaddon

Avaddon is a Windows ransomware family operated through a ransomware-as-a-service affiliate program that recruited participants from mid-2020.

Avaddon

Family profile

Avaddon is a Windows ransomware family operated through a ransomware-as-a-service affiliate program that recruited participants from mid-2020. It affected organizations worldwide, including in Latin America. Its operators are tracked as RIDDLE SPIDER, and affiliates have used SystemBC for post-exploitation activity. Distribution included Phorpiex-delivered malicious archives, phishing emails containing malicious JavaScript attachments, and macro-enabled Excel documents. Affiliates also obtained access through weak credentials on RDP and VPN services.

Developed in C++, Avaddon encrypts files on local disks and network drives using AES-256 and RSA-2048, prioritizes database files, and changes encrypted-file extensions. It enumerates running processes, shared folders, and mapped volumes, and can determine a victim's external IP address. It terminates processes that could interfere with encryption, deletes backups and volume shadow copies, and empties the Windows Recycle Bin. Avaddon establishes persistence through scheduled tasks or Registry autorun entries and bypasses User Account Control using the CMSTPLUA COM interface. Anti-analysis features include virtual-machine checks, debugger detection, and encrypted strings. Language and regional checks prevent execution on selected systems associated with Commonwealth of Independent States countries, particularly Russian-language systems.

The operation combined file encryption with threats to publish stolen victim data through a leak site and began using DDoS attacks as additional extortion pressure in January 2021. These pressure tactics were operational services rather than established capabilities of the ransomware executable. Avaddon shut down on June 11, 2021, releasing 2,934 decryption keys that Emsisoft and Coveware validated and used to support free victim recovery.

Capabilities

  • Ddos
  • Defense Evasion
  • Extortion
  • Persistence
  • Privilege Escalation
  • Reconnaissance

Samples

Recent samples

6 sandbox samples in the Derp library, newest 6 shown

Reported operators

Threat actors

2 named in public reporting
RIDDLE SPIDER

“RIDDLE SPIDER: the Avaddon ransomware operators, whose affiliates use SystemBC as a post exploitation tool.”

Bassterlord

Bassterlord, a suspected Russian-speaking threat actor who previously served as an affiliate for the LockBit ransomware gang, but also other rival RaaS operations, such as REvil, Avaddon, and RansomExx.

Exploited software

Vulnerabilities linked to Avaddon

1 CVEs

MITRE ATT&CK

Avaddon in ATT&CK

58 distinct techniques

Techniques

58 techniques
T1059.007 JavaScript T1547.001 Registry Run Keys / Startup Folder T1027 Obfuscated Files or Information T1490 Inhibit System Recovery T1685 Disable or Modify Tools T1486 Data Encrypted for Impact T1140 Deobfuscate/Decode Files or Information T1614.001 System Language Discovery T1047 Windows Management Instrumentation T1016 System Network Configuration Discovery T1106 Native API T1083 File and Directory Discovery T1548.002 Bypass User Account Control T1135 Network Share Discovery T1057 Process Discovery T1489 Service Stop T1112 Modify Registry T1559.001 Component Object Model T1036 Masquerading T1566 Phishing T1566.001 Spearphishing Attachment T1105 Ingress Tool Transfer T1059.001 PowerShell T1078 Valid Accounts T1498 Network Denial of Service T1053.005 Scheduled Task T1041 Exfiltration Over C2 Channel T1021 Remote Services T1197 BITS Jobs T1204 User Execution T1059.005 Visual Basic T1497 Virtualization/Sandbox Evasion T1537 Transfer Data to Cloud Account T1548 Abuse Elevation Control Mechanism T1622 Debugger Evasion T1082 System Information Discovery T1499 Endpoint Denial of Service T1567.003 Exfiltration to Text Storage Sites T1074 Data Staged T1189 Drive-by Compromise T1070.004 File Deletion T1202 Indirect Command Execution T1498.001 Direct Network Flood T1543.003 Windows Service T1120 Peripheral Device Discovery T1497.001 System Checks T1012 Query Registry T1133 External Remote Services T1204.002 Malicious File T1560.001 Archive via Utility T1573 Encrypted Channel T1482 Domain Trust Discovery T1055 Process Injection T1567.002 Exfiltration to Cloud Storage T1027.002 Software Packing T1069 Permission Groups Discovery T1583.003 Virtual Private Server T1071.001 Web Protocols

Reporting

Research mentioning Avaddon

Aug 11
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.

Jul 30
Splunk Research

Detection: Windows Suspicious Child Process of Consent.EXE | Splunk Security Content

Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.

Jul 22
Splunk Research

Windows Suspicious Child Of Consent.exe | Splunk Security Content

Jul 16
Register Security

Telegram shortlinks knocked offline over sanctioned VPN connection

The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.

Jul 15
Scworld

U.S. sanctions VPN provider and cryptor seller for aiding ransomware gangs | brief | SC Media

Jul 15
Xakep

Власти США наложили санкции на First VPN из-за связей с вымогателями - Хакер

Jul 14
Security Affairs

U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses

Jul 14
Cyberscoop

US sanctions First VPN and administrator for supporting ransomware | CyberScoop