Skip to content

Avaddon

Avaddon is a Windows ransomware family operated through a ransomware-as-a-service model and first observed in late 2019.

Profile source: Mallory opens in a new tab

Avaddon

Family profile

Avaddon is a Windows ransomware family operated through a ransomware-as-a-service model and first observed in late 2019. In 2020 it expanded by recruiting affiliates and went on to impact organizations globally, including victims in Latin America. The operation combined file encryption with multi-layered extortion, using a leak site to pressure victims and, by early 2021, also employing DDoS attacks as an additional coercive tactic. Avaddon later ceased operations in June 2021 and released decryption keys that enabled recovery for many victims.

Avaddon commonly spread through phishing campaigns delivering malicious attachments, including script-based downloaders and earlier macro-enabled documents. It was also observed being deployed after compromise of remote access services using weak RDP or VPN credentials. Distribution was closely associated with the Phorpiex botnet during 2020 and early 2021, which delivered Avaddon as a secondary payload through archive-based campaigns.

Technically, Avaddon was developed in C++ and used anti-analysis measures including anti-VM, anti-debugging, and encrypted strings. It encrypted files with a combination of AES-256 and RSA-2048, appended variant-specific or random extensions to encrypted files, and prioritized certain high-value data such as database files. The malware searched local disks, network drives, shared folders, and mapped volumes for content to encrypt, and it could terminate interfering processes before encryption. It also deleted backups and shadow copies and emptied the Recycle Bin to hinder recovery.

On compromised systems, Avaddon performed host discovery and environment checks, including collecting information about running processes and obtaining the victim’s external IP address. It modified Registry keys for persistence and defense evasion, used Registry Run keys and scheduled tasks to survive reboots, and attempted privilege escalation through a User Account Control bypass using the CMSTPLUA COM interface. It also avoided execution on systems configured for CIS-region languages, especially Russian, consistent with behavior seen across multiple Russian-speaking ransomware operations.

Avaddon is associated with financially motivated cybercrime rather than espionage. Its operational profile reflects the broader evolution of big-game ransomware during 2020–2021: affiliate-driven intrusions, encryption of enterprise data, theft-based extortion, public leak infrastructure, and pressure tactics beyond encryption alone.

Capabilities

  • Ddos
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Persistence
  • Privilege Escalation
  • Reconnaissance
  • Scanning

Operational record

1
YARA rules
1
Ransom notes
7
Negotiations
1
Leak sites
0 available

Credential Theft

  • Mimikatz
  • SharpDump

Defense Evasion

  • GMER
  • PowerTool
  • TDSSKiller

Discovery Enum

  • SoftPerfect NetScan

Exfiltration

  • Anonfiles
  • MEGA
  • ProtonMail
  • Sendspace

Offsec

  • PowerShell Empire
  • PowerSploit

Reported operators

Threat actors

2 named in public reporting
Bassterlord

Bassterlord, a suspected Russian-speaking threat actor who previously served as an affiliate for the LockBit ransomware gang, but also other rival RaaS operations, such as REvil, Avaddon, and RansomExx.

Exploited software

Vulnerabilities linked to Avaddon

1 CVEs

MITRE ATT&CK

Avaddon in ATT&CK

59 distinct techniques

Techniques

59 techniques
T1486 Data Encrypted for Impact T1057 Process Discovery T1112 Modify Registry T1016 System Network Configuration Discovery T1106 Native API T1135 Network Share Discovery T1548.002 Bypass User Account Control T1559.001 Component Object Model T1083 File and Directory Discovery T1547.001 Registry Run Keys / Startup Folder T1140 Deobfuscate/Decode Files or Information T1562 Impair Defenses T1036 Masquerading T1566 Phishing T1566.001 Spearphishing Attachment T1490 Inhibit System Recovery T1105 Ingress Tool Transfer T1059.001 PowerShell T1614.001 System Language Discovery T1078 Valid Accounts T1498 Network Denial of Service T1053.005 Scheduled Task T1041 Exfiltration Over C2 Channel T1489 Service Stop T1021 Remote Services T1197 BITS Jobs T1204 User Execution T1059.005 Visual Basic T1497 Virtualization/Sandbox Evasion T1537 Transfer Data to Cloud Account T1059.007 JavaScript T1548 Abuse Elevation Control Mechanism T1622 Debugger Evasion T1082 System Information Discovery T1499 Endpoint Denial of Service T1567.003 Exfiltration to Text Storage Sites T1074 Data Staged T1189 Drive-by Compromise T1070.004 File Deletion T1202 Indirect Command Execution T1498.001 Direct Network Flood T1562.001 Disable or Modify Tools T1543.003 Windows Service T1120 Peripheral Device Discovery T1027 Obfuscated Files or Information T1497.001 System Checks T1012 Query Registry T1133 External Remote Services T1047 Windows Management Instrumentation T1204.002 Malicious File T1560.001 Archive via Utility T1573 Encrypted Channel T1482 Domain Trust Discovery T1055 Process Injection T1567.002 Exfiltration to Cloud Storage T1027.002 Software Packing T1069 Permission Groups Discovery T1583.003 Virtual Private Server T1071.001 Web Protocols

Reporting

Research mentioning Avaddon

Aug 11
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.

Jul 30
Splunk Research

Detection: Windows Suspicious Child Process of Consent.EXE | Splunk Security Content

Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.

Jul 22
Splunk Research

Windows Suspicious Child Of Consent.exe | Splunk Security Content

Jul 16
Register Security

Telegram shortlinks knocked offline over sanctioned VPN connection

The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.

Jul 15
Scworld

U.S. sanctions VPN provider and cryptor seller for aiding ransomware gangs | brief | SC Media

Jul 15
Xakep

Власти США наложили санкции на First VPN из-за связей с вымогателями - Хакер

Jul 14
Security Affairs

U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses

Jul 14
Cyberscoop

US sanctions First VPN and administrator for supporting ransomware | CyberScoop

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.