NoEscape is a financially motivated ransomware-as-a-service (RaaS) operation that emerged in May 2023 and is widely assessed to be a rebrand or spin-off of Avaddon. The group conducts multi-extortion ransomware operations, combining file encryption with data theft and publication threats through a leak site, and has also been associated with additional coercive options such as DDoS or spam-based pressure. NoEscape has been observed recruiting or supporting affiliates and providing payload-building capability for both Windows and Linux environments. Victimology reported for 2023 indicates a concentration on organizations in the United States, with manufacturing, education, and construction among the most affected sectors. Individual publicly claimed victims have included government-related bodies, universities, healthcare organizations, and industrial firms in multiple countries. The operation has also been noted for referencing GDPR-related pressure in extortion messaging. NoEscape is reported to avoid targeting CIS countries, a pattern commonly associated with Russian-speaking ransomware ecosystems. Operationally, NoEscape affiliates have been linked to initial access via malicious downloads and email attachments, as well as exploitation of public-facing Microsoft Exchange vulnerabilities such as ProxyShell. Post-compromise activity has included credential dumping, use of valid accounts, lateral movement over RDP, stealthy command execution through COM and WMI, persistence via scheduled tasks, and data exfiltration to cloud storage. Incident reporting also describes tunneling RDP over SSH, use of remote administration software, and attempts to disable or evade endpoint defenses through PowerShell-based exclusions and vulnerable-driver abuse. The malware itself includes anti-debugging checks, language-based anti-CIS execution controls, host and drive discovery, process termination using Windows Restart Manager APIs, deletion of backups and shadow copies, service stopping, event-log clearing, and encryption workflows using embedded configuration data and public-key cryptography. Persistence has been observed through a scheduled task commonly used to relaunch the encryptor. NoEscape has also been discussed in the context of affiliate movement within the broader ransomware ecosystem, including recruitment efforts by LockBit after disruption or loss of trust in rival programs. Reports in late 2023 indicated the operation’s leak site went offline amid affiliate allegations of an exit scam, but NoEscape remains a recognized ransomware brand within the 2023–2024 criminal ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a distinct RaaS program advertised on RAMP.
Claimed responsibility for a prior ransomware-related breach of the University of Hawaii, alleging theft of 65GB of sensitive data.
Ransomware operation referenced as having affiliates that partnered with Iranian actors in profit-sharing arrangements.
Unconfirmed association with suspicious activity involving the Powerhouse domain in late 2023; not publicly attributed as the confirmed actor behind the 2026-disclosed breach.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.