Credential Theft
- Mimikatz
- SharpDump
Avaddon is a Windows ransomware family operated through a ransomware-as-a-service model and first observed in late 2019.
Profile source: Mallory opens in a new tabAvaddon
Avaddon is a Windows ransomware family operated through a ransomware-as-a-service model and first observed in late 2019. In 2020 it expanded by recruiting affiliates and went on to impact organizations globally, including victims in Latin America. The operation combined file encryption with multi-layered extortion, using a leak site to pressure victims and, by early 2021, also employing DDoS attacks as an additional coercive tactic. Avaddon later ceased operations in June 2021 and released decryption keys that enabled recovery for many victims.
Avaddon commonly spread through phishing campaigns delivering malicious attachments, including script-based downloaders and earlier macro-enabled documents. It was also observed being deployed after compromise of remote access services using weak RDP or VPN credentials. Distribution was closely associated with the Phorpiex botnet during 2020 and early 2021, which delivered Avaddon as a secondary payload through archive-based campaigns.
Technically, Avaddon was developed in C++ and used anti-analysis measures including anti-VM, anti-debugging, and encrypted strings. It encrypted files with a combination of AES-256 and RSA-2048, appended variant-specific or random extensions to encrypted files, and prioritized certain high-value data such as database files. The malware searched local disks, network drives, shared folders, and mapped volumes for content to encrypt, and it could terminate interfering processes before encryption. It also deleted backups and shadow copies and emptied the Recycle Bin to hinder recovery.
On compromised systems, Avaddon performed host discovery and environment checks, including collecting information about running processes and obtaining the victim’s external IP address. It modified Registry keys for persistence and defense evasion, used Registry Run keys and scheduled tasks to survive reboots, and attempted privilege escalation through a User Account Control bypass using the CMSTPLUA COM interface. It also avoided execution on systems configured for CIS-region languages, especially Russian, consistent with behavior seen across multiple Russian-speaking ransomware operations.
Avaddon is associated with financially motivated cybercrime rather than espionage. Its operational profile reflects the broader evolution of big-game ransomware during 2020–2021: affiliate-driven intrusions, encryption of enterprise data, theft-based extortion, public leak infrastructure, and pressure tactics beyond encryption alone.
Reported operators
Bassterlord, a suspected Russian-speaking threat actor who previously served as an affiliate for the LockBit ransomware gang, but also other rival RaaS operations, such as REvil, Avaddon, and RansomExx.
"June 1, 2020 RIDDLE SPIDER's Avaddon"
Exploited software
MITRE ATT&CK
Reporting
A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.
Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.
The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.