Overview

Platforms: Windows
Variants: —
Extensions: —
ATT&CK software: —
Initial access: —
Top countries: —
Observed sectors: —
Tracked victims: 142

Attribution

No supported attribution to a specific operator, developer, or related threat actor is currently available.

Affiliates

No affiliate information available.

Activity

Recent Observations

Avaddon shuts down
June 2021
Operational closure
The operation closed its ransomware infrastructure and released 2,934 victim decryption keys.
AXA Asia ransomware attack
May 2021
Major incident
AXA confirmed a ransomware incident affecting Asia Assistance operations in Thailand, Malaysia, Hong Kong and the Philippines; government reporting attributed the attack to Avaddon.
DDoS added to extortion model
January 2021
Extortion evolution
Avaddon expanded its extortion model by adding distributed denial-of-service attacks against victims that refused to pay.
Data leak extortion introduced
August 2020
Extortion evolution
Avaddon began combining ransomware encryption with theft and publication of victim data.

TTPs

ATT&CK coverage: 7 techniques · 5 tactics
T1059.007 JavaScript
VERIFIED
Execution
Avaddon was delivered through malicious JavaScript downloaders during early campaigns.
T1548.002 Bypass User Account Control
VERIFIED
Privilege Escalation / Defense Evasion
Avaddon could bypass User Account Control using the CMSTPLUA COM interface.
T1547.001 Registry Run Keys / Startup Folder
VERIFIED
Persistence / Privilege Escalation
Avaddon used registry run keys to establish persistence.
Show more TTPs (4)
T1135 Network Share Discovery
VERIFIED
Discovery
Avaddon enumerated shared folders and mapped network volumes before encryption.
T1490 Inhibit System Recovery
VERIFIED
Impact
Avaddon deleted backups and volume shadow copies using native Windows utilities.
T1489 Service Stop
VERIFIED
Impact
Avaddon attempted to stop services and database processes that could interfere with file encryption.
T1486 Data Encrypted for Impact
VERIFIED
Impact
Avaddon encrypted victim files using a combination of AES-256 and RSA cryptography.

Victims

AXA Asia Assistance CONFIRMED
May 2021 Multiple Insurance
Insurance organization in Multiple.

CVEs

No CVE associations available.

Infrastructure

Avaddon leak site
Avaddon operated Tor-hosted leak infrastructure to publish stolen victim information and support double-extortion operations.
Payment infrastructure
Tor-hosted payment services were used to provide ransom instructions, communicate with victims and distribute decryptors following payment.
DDoS capability
Avaddon incorporated distributed denial-of-service attacks as an additional pressure mechanism against non-paying victims.

Timeline

2021-06
Avaddon shuts down
Avaddon terminated its operation and released 2,934 decryption keys covering individual victims.
2021-05
AXA Asia attack
AXA Asia Assistance operations in several Asian markets were affected by a ransomware incident attributed to Avaddon.
2021-01
DDoS extortion added
The operation expanded to a multi-extortion model by launching denial-of-service attacks against non-paying victims.
Show more events (2)
2020-08
Double extortion introduced
Avaddon added data theft and publication threats to its ransomware business model.
2020-06
Avaddon operation emerges
Avaddon appeared as a ransomware-as-a-service operation and began spreading through malicious JavaScript campaigns.

Sources