Skip to content

Avaddon

Avaddon is a Windows ransomware family and ransomware operation active in large-scale criminal campaigns from at least 2020 through 2021.

Profile source: Mallory opens in a new tab

Avaddon

Family profile

Avaddon is a Windows ransomware family and ransomware operation active in large-scale criminal campaigns from at least 2020 through 2021. It became especially notable for high-volume email distribution activity and later for intrusions that increasingly relied on remote access services such as RDP and VPN infrastructure rather than direct email delivery. Avaddon has also been linked to use of criminal anonymity infrastructure such as First VPN Service for reconnaissance and intrusion support.

Avaddon is associated with common big-game ransomware tradecraft. It performs locale and keyboard-layout checks to avoid infecting systems associated with Commonwealth of Independent States countries, a pattern frequently seen in Russian-speaking cybercrime ecosystems. On compromised Windows systems it modifies the registry for persistence and user account control bypass, attempts to identify and stop anti-malware products, and uses native administrative tooling to impair recovery by deleting backups and shadow copies, including via WMIC. Execution has been observed through a malicious JScript downloader, and historical reporting also ties Avaddon to major malspam campaigns.

The malware targets Windows environments and is relevant across enterprise victims, with reporting connecting the broader operation to attacks affecting businesses and other organizations. Avaddon is widely recognized as a ransomware family, and later ransomware activity such as NoEscape has been assessed by some researchers as a likely rebranding or descendant of Avaddon.

Capabilities

  • Defense Evasion
  • Persistence
  • Reconnaissance

Operational record

1
YARA rules
1
Ransom notes
7
Negotiations
1
Leak sites
0 available

Credential Theft

  • Mimikatz
  • SharpDump

Defense Evasion

  • GMER
  • PowerTool
  • TDSSKiller

Discovery Enum

  • SoftPerfect NetScan

Exfiltration

  • Anonfiles
  • MEGA
  • ProtonMail
  • Sendspace

Offsec

  • PowerShell Empire
  • PowerSploit

Reported operators

Threat actors

1 named in public reporting

MITRE ATT&CK

Avaddon in ATT&CK

34 distinct techniques

Reporting

Research mentioning Avaddon

Jul 16
Register Security

Telegram shortlinks knocked offline over sanctioned VPN connection

The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.

Jul 15
Scworld

U.S. sanctions VPN provider and cryptor seller for aiding ransomware gangs | brief | SC Media

Jul 15
Xakep

Власти США наложили санкции на First VPN из-за связей с вымогателями - Хакер

Jul 14
Security Affairs

U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses

Jul 14
Cyberscoop

US sanctions First VPN and administrator for supporting ransomware | CyberScoop

Jul 14
Chainalysis

“Stern” Ransomware Operator Sanctioned by EU

Jul 14
Cyber Security News

US Treasury Sanctions VPN Service that Helped Ransomware Actors to Attack Organizations

Jul 14
The Hacker News

U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.