Avaddon is a Windows ransomware family operated through a ransomware-as-a-service model and first observed in late 2019. In 2020 it expanded by recruiting affiliates and went on to impact organizations globally, including victims in Latin America. The operation combined file encryption with multi-layered extortion, using a leak site to pressure victims and, by early 2021, also employing DDoS attacks as an additional coercive tactic. Avaddon later ceased operations in June 2021 and released decryption keys that enabled recovery for many victims.
Avaddon commonly spread through phishing campaigns delivering malicious attachments, including script-based downloaders and earlier macro-enabled documents. It was also observed being deployed after compromise of remote access services using weak RDP or VPN credentials. Distribution was closely associated with the Phorpiex botnet during 2020 and early 2021, which delivered Avaddon as a secondary payload through archive-based campaigns.
Technically, Avaddon was developed in C++ and used anti-analysis measures including anti-VM, anti-debugging, and encrypted strings. It encrypted files with a combination of AES-256 and RSA-2048, appended variant-specific or random extensions to encrypted files, and prioritized certain high-value data such as database files. The malware searched local disks, network drives, shared folders, and mapped volumes for content to encrypt, and it could terminate interfering processes before encryption. It also deleted backups and shadow copies and emptied the Recycle Bin to hinder recovery.
On compromised systems, Avaddon performed host discovery and environment checks, including collecting information about running processes and obtaining the victim’s external IP address. It modified Registry keys for persistence and defense evasion, used Registry Run keys and scheduled tasks to survive reboots, and attempted privilege escalation through a User Account Control bypass using the CMSTPLUA COM interface. It also avoided execution on systems configured for CIS-region languages, especially Russian, consistent with behavior seen across multiple Russian-speaking ransomware operations.
Avaddon is associated with financially motivated cybercrime rather than espionage. Its operational profile reflects the broader evolution of big-game ransomware during 2020–2021: affiliate-driven intrusions, encryption of enterprise data, theft-based extortion, public leak infrastructure, and pressure tactics beyond encryption alone.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The security researcher noted that all the Pulse Secure VPN servers included in the list were running a firmware version vulnerable to the CVE-2019-11510 vulnerability. Bank Security believes that the hacker who compiled this list scanned the entire internet IPv4 address space for Pulse Secure VPN servers, used an exploit for the CVE-2019-11510 vulnerability to gain access to systems, dump server details (including usernames and passwords), and then collected all the information in one central repository.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Bassterlord, a suspected Russian-speaking threat actor who previously served as an affiliate for the LockBit ransomware gang, but also other rival RaaS operations, such as REvil, Avaddon, and RansomExx.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
más adelante hacer uso de credenciales de acceso débiles en servicios de acceso remoto, como RDP y redes VPN
El código JScript a su vez ejecuta comandos de Powershell para descargar el ransomware de un servidor web
también se ha visto utilizar en sus comienzos archivos Excel con macros maliciosas
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
After the attachment is downloaded and ran, it uses a PowerShell command and the BITSAdmin command-line tool to download and run the ransomware payload.
incluyen un archivo JScript malicioso adjunto... para hacerle creer a la potencial víctima que se trata de un archivo comprimido que contiene una foto comprometedora
Avaddon bypasses UAC using the CMSTPLUA COM interface... LockBit 3.0 can bypass UAC to execute code with elevated privileges through an elevated Component Object Model (COM) interface. Medusa Group has attempted to bypass UAC using Component Object Model (COM) interface.
más adelante hacer uso de credenciales de acceso débiles en servicios de acceso remoto, como RDP y redes VPN
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
After the attachment is downloaded and ran, it uses a PowerShell command and the BITSAdmin command-line tool to download and run the ransomware payload.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
más adelante hacer uso de credenciales de acceso débiles en servicios de acceso remoto, como RDP y redes VPN
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
As the bot loader updates, the key values change to reflect new files, randomized file paths, and masqueraded system files. The example below illustrates a change from SVCHOST to LSASS
más adelante hacer uso de credenciales de acceso débiles en servicios de acceso remoto, como RDP y redes VPN
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
APT1 listed connected network shares. APT32 used the net view command to show all shares available, including the administrative shares such as C$ and ADMIN$. APT41 used the net share command as part of network reconnaissance.
The criminal group behind the Avaddon ransomware has shut down its operation today and released decryption keys for past victims. | The decryptor will take the 2,934 decryption keys and allow past Avaddon victims to decrypt their files for free if they still have the encrypted files around and have not deleted the data.
61 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
93 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in a list of ransomware operations known for affiliate programs and leak blogs.
A named ransomware family cited as one of the groups that used the sanctioned VPN service 1VPNS for reconnaissance and intrusions.
Named ransomware group/family cited as one of the users of First VPN infrastructure for reconnaissance, initial access, data theft, and other attacks.
A ransomware family cited as one of the ransomware types whose operators used First VPN to hide attack origins, deploy malware, and manage stolen data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.