NoEscape is a financially motivated ransomware family and ransomware-as-a-service operation that emerged in 2023 and is widely assessed as likely related to, or a rebrand of, Avaddon. It supports attacks against Windows and Linux environments and is used in multi-extortion campaigns that combine file encryption with data theft and public shaming through a Tor-based leak site. Some reporting also indicates the operation offered additional coercive options such as DDoS or spam-based pressure. Victimology observed in 2023 showed a concentration on organizations in the United States, with manufacturing, education, and construction among affected sectors, while the malware includes logic commonly associated with CIS-avoidance behavior seen in Russian-speaking ransomware ecosystems.
On Windows, NoEscape includes anti-debugging checks, language-based execution filtering, host and drive discovery, process and service termination, backup and shadow-copy deletion, event-log clearing, and stealthier command execution through COM and WMI. It can tamper with UAC-related settings, copy itself into user-space locations, and establish persistence via a scheduled task commonly named to resemble a system update. The encryptor uses embedded configuration data protected with RC4 and Base64 decoding, leverages Windows CryptoAPI in its encryption workflow, and uses public-key cryptography to protect generated encryption material. It also collects host metadata and appends encrypted victim information to the ransom note.
Intrusions associated with NoEscape affiliates have involved exploitation of internet-facing Microsoft Exchange servers via ProxyShell, webshell deployment, credential dumping from LSASS, use of valid accounts, lateral movement over RDP, tunneling for persistent access, and exfiltration to cloud storage prior to ransomware execution. Separate reporting also describes NoEscape operators acquiring previously established access from initial access brokers after long-dwelling Exchange compromises, then using credential-capture techniques, remote administration tools, network enumeration, lateral movement, and likely exfiltration before deployment. Public reporting has also linked Iranian actors to partnerships with affiliates of the NoEscape ecosystem for revenue-sharing arrangements. Overall, NoEscape is best characterized as a mature double-extortion ransomware operation with cross-platform payload generation, conventional enterprise-impacting tradecraft, and affiliate-driven intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“This post will delve into a recent incident response engagement… involving the Ransomware-as-a-Service known as NoEscape.”
“This post will delve into a recent incident response engagement… involving the Ransomware-as-a-Service known as NoEscape.”
“This post will delve into a recent incident response engagement… involving the Ransomware-as-a-Service known as NoEscape.”
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“This post will delve into a recent incident response engagement… involving the Ransomware-as-a-Service known as NoEscape.”
1 distinct technique documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation whose affiliates were reportedly partnered with Iranian actors for financially motivated activity.
A ransomware-as-a-service program advertised on RAMP.
Ransomware operation that claims to breach organizations and steal sensitive data (e.g., 65GB in the cited June 2023 claim), typically to extort victims.
Ransomware operation referenced as having affiliates that partnered with Iranian actors for monetization.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.