top of page
Avaddon
Name
Category
Type
Targeted OS
Description
Information
Avaddon
Malware
Ransomware
Big Game Hunting
Windows & Linux
(Awake Security) Avaddon is a cryptolocker ransomware written in C++ that is best known for encrypting files and changing the file extension to .avdn. The ransomware also deletes the volume shadow copies and other system backups and typically demands a ransom ranging between $150 and $900. Since the ransomware uses strong encryption algorithms like AES256 and RSA2048, no decryptor is available and it is impossible to decrypt the file without the key that was used to encrypt it. This ransomware is sold similar to other Ransomware-as-a-service(RaaS) like REvil. Thus, even someone with limited technical background can become an �affiliate� to spread the malware. In return, the profit gets shared between the threat actor and the affiliate. In this blog post we dissect this malware and discuss methods to perform threat hunting for the Avaddon ransomware family.
https://awakesecurity.com/blog/threat-hunting-for-avaddon-ransomware/
https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/ransomware-report-avaddon-and-new-techniques-emerge-industrial-sector-targeted
https://www.subexsecure.com/pdf/malware-reports/June-2020/Avaddon_Ransomware.pdf
https://arxiv.org/pdf/2102.04796.pdf
https://labs.sentinelone.com/avaddon-raas-breaks-public-decryptor-continues-on-rampage/
https://www.domaintools.com/resources/blog/avaddon-the-latest-raas-to-jump-on-the-extortion-bandwagon
https://www.offensive-hackers.com/2020/06/this-new-avaddon-ransomware-targeting-worldwide-users.html
https://www.proofpoint.com/us/blog/security-briefs/ransomware-initial-payload-reemerges-avaddon-philadelphia-mr-robot-and-more
https://asec.ahnlab.com/en/17411/
https://www.cybereason.com/blog/cybereason-vs.-avaddon-ransomware
https://www.cyber.gov.au/sites/default/files/2021-05/2021-003%20Ongoing%20campaign%20using%20Avaddon%20Ransomware%20-%2020210508.pdf
Malpedia
Alienvault OTX
Playbook
https://www.nomoreransom.org/uploads/Avaddon_documentation.pdf
https://www.nomoreransom.org/uploads/Avaddon_documentation_new.pdf
CISA
Other Information
Mitre
Mitre Techniques
Mitre Techniques Navigator Link
NIL
https://www.mandiant.com/resources/blog/chasing-avaddon-ransomware
https://atos.net/en/lp/securitydive/avaddon-ransomware-analysis
['T1548', 'T1547', 'T1059', 'T1486', 'T1140', 'T1083', 'T1562', 'T1490', 'T1112', 'T1106', 'T1135', 'T1027', 'T1057', 'T1489', 'T1614', 'T1016', 'T1047']
bottom of page