Skip to content

AvosLocker

AvosLocker is a ransomware family and ransomware-as-a-service operation first identified in 2021 that primarily targets enterprise environments.

Profile source: Mallory opens in a new tab

AvosLocker

Family profile

AvosLocker is a ransomware family and ransomware-as-a-service operation first identified in 2021 that primarily targets enterprise environments. It initially focused on Windows systems and later expanded to Linux, including variants designed to encrypt VMware ESXi infrastructure. The operation is associated with double-extortion, combining file encryption with data theft and public leak-site pressure, and has also been reported to monetize stolen data through auction-style exposure when victims refuse to pay.

On Windows, AvosLocker encrypts business data, drops ransom notes in affected directories, and uses multithreaded execution, mutex-based instance control, drive and network-resource enumeration, and file and folder exclusion logic. Reported analyses describe variants using strong cryptographic schemes including AES-256 in some Windows-focused reporting and ChaCha20-protected metadata with RSA in other technical analyses. The malware has also been observed using defense-evasion measures such as hiding its console window with the ShowWindow API, modifying or disabling security controls including Windows Defender, and abusing Safe Mode boot to impair endpoint protections.

AvosLocker’s Linux branch, often referred to as AvosLinux, is an ELF-based encryptor aimed at VMware ESXi hosts and VMFS-backed virtual infrastructure. It accepts command-line parameters for target path and thread count, uses multithreading with synchronization controls, checks for ESXi and VMFS-related environments, and attempts to stop running virtual machines before encryption so virtual disk and related files can be processed successfully. Multiple reports describe ESXi-focused behavior including use of esxcli to terminate VMs prior to encrypting host data.

Initial access associated with AvosLocker activity has included spam or spearphishing campaigns, exploitation of exposed remote access services, weak RDP credentials, and exploitation of Microsoft Exchange ProxyShell-related vulnerabilities. Post-compromise activity attributed to AvosLocker operators or affiliates includes credential theft with Mimikatz, Active Directory discovery, lateral movement using common administrative tooling, exfiltration of victim data before encryption, and disabling or terminating security products and recovery mechanisms. The operation has also been linked to affiliate recruitment and broader RaaS enablement.

AvosLocker is notable for targeting organizations rather than commodity consumer victims, with emphasis on business disruption, extortion leverage, and virtualization infrastructure impact. Its evolution from Windows ransomware to ESXi-capable Linux encryptors, combined with persistent use of defense evasion and data-theft-driven extortion, places it among the more operationally mature enterprise ransomware families of its period.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Privilege Escalation
  • Reconnaissance

Operational record

1
YARA rules
1
Ransom notes
2
Leak sites
0 available

Credential Theft

  • LaZagne
  • Mimikatz
  • XenArmor

Defense Evasion

  • Avast Anti-Rootkit driver

Discovery Enum

  • NirSoft WinLister
  • Nmap
  • SoftPerfect NetScan

Exfiltration

  • FileZilla
  • Gofile[.]io
  • PSCP
  • RClone
  • share[.]riseup[.]net

LOLBAS

  • PsExec
  • WMIC

Networking

  • Chisel
  • Ligolo

Offsec

  • Cobalt Strike
  • Sliver

RMM Tools

  • AnyDesk
  • Atera
  • PDQ Deploy
  • Splashtop
  • TacticalRMM

Reported operators

Threat actors

1 named in public reporting
AvosLocker

AvosLocker is a ransomware group that was identified in 2021, specifically targeting Windows machines. Now a new variant of AvosLocker malware is also targeting Linux environments.

Exploited software

Vulnerabilities linked to AvosLocker

8 CVEs

MITRE ATT&CK

AvosLocker in ATT&CK

30 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.