Riddle Spider is the threat actor associated with operating the Avaddon ransomware-as-a-service (RaaS) enterprise. Active in the Avaddon campaign from June 2020 to June 2021, the group used an affiliate model in which operators managed development and overall administration while affiliates conducted intrusions and shared profits. Avaddon was a double-extortion ransomware operation with a dedicated leak site, combining file encryption with the threat of publishing stolen data. Riddle Spider’s Avaddon activity targeted Windows environments and relied on affiliates for initial access, including the use of compromised credentials and Remote Desktop Protocol access. The operation also used custom web shells for persistence and deployed SystemBC for remote host interaction, alongside post-exploitation tooling such as Empire and PowerSploit. Reported tradecraft included host reconnaissance, data exfiltration, lateral movement, privilege escalation, persistence, and defense evasion. Avaddon encrypted local and mapped network shares and incorporated anti-recovery measures such as deleting shadow copies and interfering with restart and recovery mechanisms. The malware and associated operations showed extensive defense-evasion behavior, including geographic checks designed to avoid execution in CIS-language environments, termination of services and processes, and configuration obfuscation. Avaddon also embedded victim and host information into ransom-note workflows. Riddle Spider has been associated with the use of SystemBC, a malware family commonly used to provide backdoor access, persistence, proxying, reconnaissance support, and follow-on payload delivery during ransomware intrusions. Riddle Spider is best known through its association with Avaddon and may appear under related naming variants including RiddleSpider and RiddleSpider (Avaddon).
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Riddle Spider is known for operating the Avaddon ransomware-as-a-service (RaaS) campaign from June 2020 to June 2021, leveraging double extortion tactics and an affiliate profit-sharing model. The group targets Windows systems, encrypts files, and threatens to leak stolen data if ransom demands are not met.
Listed as one of multiple threat groups associated with using SystemBC.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.