Avaddon, also known as Avaddon ransomware, was a financially motivated ransomware-as-a-service operation first observed in late 2019. It began recruiting affiliates in mid-2020 through cybercriminal forums and compromised companies and organizations worldwide, including in Latin America. Its affiliate network included Bassterlord, who also worked with other ransomware operations. Avaddon combined file encryption with theft of sensitive data and threats to publish it on a Tor-hosted leak site. It also sometimes used data-theft-only extortion. In January 2021, the operation added distributed denial-of-service attacks as an additional pressure mechanism, extending its approach to triple extortion. Initial access and malware distribution involved phishing emails with malicious JavaScript attachments or macro-enabled Excel documents, as well as weak credentials on RDP and VPN services. JavaScript delivery chains used PowerShell to download and execute the ransomware. The C++ ransomware encrypted files on local disks and network drives using AES-256 and RSA-2048, prioritizing database files. It attempted privilege escalation through a User Account Control bypass and established persistence through scheduled tasks or registry Run entries. Anti-analysis features included virtual-machine detection, debugger checks, and encrypted strings. It terminated processes that could interfere with encryption and deleted backups and volume shadow copies to impair recovery. Language checks prevented malicious execution on systems configured for certain Commonwealth of Independent States languages, particularly Russian. Following the May 2021 Colonial Pipeline incident, Avaddon announced that it would stop public forum advertising, continue privately with existing affiliates and referrals, and prohibit attacks against government, healthcare, and educational organizations. The operation shut down on June 11, 2021, and released 2,934 decryption keys. Emsisoft and Coveware validated the keys, enabling free recovery assistance for victims.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
60 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
24 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in a list of ransomware groups known for affiliate programs and leak blogs.
Referenced as one of the ransomware groups that used First VPN infrastructure for network reconnaissance and intrusions.
Referenced only for comparison, as Haron showed similarities to Avaddon in ransom note and leak site characteristics.
Mentioned as adopting triple extortion tactics after SunCrypt and RagnarLocker.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.