Overview
Platforms:
Windows
Variants:
—
Extensions:
—
ATT&CK software:
—
Initial access:
—
Top countries:
—
Observed sectors:
—
Tracked victims:
142
Attribution
No supported attribution to a specific operator, developer, or related threat actor is currently available.
Affiliates
No affiliate information available.
Activity
Recent Observations
Avaddon shuts down
June 2021
Operational closure
The operation closed its ransomware infrastructure and released 2,934 victim decryption keys.
AXA Asia ransomware attack
May 2021
Major incident
AXA confirmed a ransomware incident affecting Asia Assistance operations in Thailand, Malaysia, Hong Kong and the Philippines; government reporting attributed the attack to Avaddon.
DDoS added to extortion model
January 2021
Extortion evolution
Avaddon expanded its extortion model by adding distributed denial-of-service attacks against victims that refused to pay.
Data leak extortion introduced
August 2020
Extortion evolution
Avaddon began combining ransomware encryption with theft and publication of victim data.
TTPs
ATT&CK coverage:
7 techniques
· 5 tactics
T1059.007
JavaScript
VERIFIEDExecution
Avaddon was delivered through malicious JavaScript downloaders during early campaigns.
T1548.002
Bypass User Account Control
VERIFIEDPrivilege Escalation / Defense Evasion
Avaddon could bypass User Account Control using the CMSTPLUA COM interface.
T1547.001
Registry Run Keys / Startup Folder
VERIFIEDPersistence / Privilege Escalation
Avaddon used registry run keys to establish persistence.
Show more TTPs (4)
T1135
Network Share Discovery
VERIFIEDDiscovery
Avaddon enumerated shared folders and mapped network volumes before encryption.
T1490
Inhibit System Recovery
VERIFIEDImpact
Avaddon deleted backups and volume shadow copies using native Windows utilities.
T1489
Service Stop
VERIFIEDImpact
Avaddon attempted to stop services and database processes that could interfere with file encryption.
T1486
Data Encrypted for Impact
VERIFIEDImpact
Avaddon encrypted victim files using a combination of AES-256 and RSA cryptography.
Victims
AXA Asia Assistance
CONFIRMED
Insurance organization in Multiple.
CVEs
No CVE associations available.
Infrastructure
Avaddon leak site
Avaddon operated Tor-hosted leak infrastructure to publish stolen victim information and support double-extortion operations.
Payment infrastructure
Tor-hosted payment services were used to provide ransom instructions, communicate with victims and distribute decryptors following payment.
DDoS capability
Avaddon incorporated distributed denial-of-service attacks as an additional pressure mechanism against non-paying victims.
Timeline
2021-06
Avaddon shuts down
Avaddon terminated its operation and released 2,934 decryption keys covering individual victims.
2021-05
AXA Asia attack
AXA Asia Assistance operations in several Asian markets were affected by a ransomware incident attributed to Avaddon.
2021-01
DDoS extortion added
The operation expanded to a multi-extortion model by launching denial-of-service attacks against non-paying victims.
Show more events (2)
2020-08
Double extortion introduced
Avaddon added data theft and publication threats to its ransomware business model.
2020-06
Avaddon operation emerges
Avaddon appeared as a ransomware-as-a-service operation and began spreading through malicious JavaScript campaigns.
Sources
Avaddon ransomware: an in-depth analysis and decryption of infected systems
Computers & Security / Yuste and Pastrana