Avaddon is a Windows ransomware family distributed through a ransomware-as-a-service affiliate program. It encrypts victim files using AES-256 and RSA-2048 and appends a random extension to encrypted files. It uses the Windows Crypto API to generate AES keys. Its discovery capabilities include enumerating running processes, shared folders, and mapped volumes, and collecting the victim's external IP address. Avaddon establishes persistence through Registry Run keys, modifies the Windows Registry, and bypasses User Account Control using the CMSTPLUA COM interface. It also decrypts obfuscated strings during execution.
The Avaddon operation is associated with RIDDLE SPIDER, whose affiliates have used SystemBC as a post-exploitation tool. Its extortion model included file encryption and publication of stolen data through a leak site, with some activity involving extortion without encryption. Beginning in January 2021, the operation also used distributed denial-of-service attacks to pressure victims into paying. Avaddon revised its affiliate targeting rules following the Colonial Pipeline attack and shut down in June 2021. Free decryption tools are available for Avaddon-encrypted files.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The security researcher noted that all the Pulse Secure VPN servers included in the list were running a firmware version vulnerable to the CVE-2019-11510 vulnerability. Bank Security believes that the hacker who compiled this list scanned the entire internet IPv4 address space for Pulse Secure VPN servers, used an exploit for the CVE-2019-11510 vulnerability to gain access to systems, dump server details (including usernames and passwords), and then collected all the information in one central repository.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Avaddon ransomware gang updating its affiliates rules following the Colonial Pipeline disaster.
“RIDDLE SPIDER: the Avaddon ransomware operators, whose affiliates use SystemBC as a post exploitation tool.”
Bassterlord, a suspected Russian-speaking threat actor who previously served as an affiliate for the LockBit ransomware gang, but also other rival RaaS operations, such as REvil, Avaddon, and RansomExx.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
Avaddon bypasses UAC using the CMSTPLUA COM interface... LockBit 3.0 can bypass UAC to execute code with elevated privileges through an elevated Component Object Model (COM) interface. Medusa Group has attempted to bypass UAC using Component Object Model (COM) interface.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
The criminal group behind the Avaddon ransomware has shut down its operation today and released decryption keys for past victims. | The decryptor will take the 2,934 decryption keys and allow past Avaddon victims to decrypt their files for free if they still have the encrypted files around and have not deleted the data.
63 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
101 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as ransomware historically associated with RIDDLE SPIDER affiliates that use SystemBC.
Mentioned in a list of ransomware operations known for affiliate programs and leak blogs.
A named ransomware family cited as one of the groups that used the sanctioned VPN service 1VPNS for reconnaissance and intrusions.
Named ransomware group/family cited as one of the users of First VPN infrastructure for reconnaissance, initial access, data theft, and other attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.