Avos Locker is a ransomware-as-a-service family active against Windows environments and, in some observed cases, VMware ESXi infrastructure. It is notable for using Safe Mode reboots on compromised Windows systems to reduce the effectiveness of endpoint security products that do not fully operate in that mode. Operators have used legitimate administration and remote-access tooling to prepare victim systems, maintain control during Safe Mode operation, and orchestrate ransomware deployment across multiple hosts.
Observed tradecraft includes the use of PDQ Deploy to push batch scripts remotely, creation of administrative local accounts, configuration of automatic logon after reboot, and execution of the ransomware payload through fileless or minimally written mechanisms. Avos Locker activity has also involved attempts to disable or sabotage security controls, including Windows Defender, Windows Update, and multiple third-party endpoint products. In some incidents, operators modified Safe Mode boot settings so remote-access software could continue functioning after reboot, allowing them to retry execution manually if automated deployment failed.
Associated post-compromise behavior includes use of encrypted tunneling utilities as back channels, PowerShell-based execution, and signs of lateral movement within victim networks. A Linux variant targeting VMware ESXi has been observed terminating running virtual machines before encrypting virtual machine files, indicating an ability to impact virtualized enterprise infrastructure in addition to standard Windows endpoints.
Avos Locker has been associated with hands-on-keyboard intrusions that rely on remote administration tools and exploitation of vulnerabilities as access enablers. The family fits the broader double-extortion-era ransomware ecosystem in which affiliates combine remote access, defense evasion, lateral movement, and centralized deployment to maximize operational impact across enterprise networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers also used the batch script to create a new user account on the infected machine ( newadmin ) and give it a password ( password123456 ), and add it to the Administrators user group.
These orchestration scripts modified or deleted Registry keys that effectively sabotaged the services or processes belonging to specific endpoint security tools... The penultimate step in the infection process is the creation of a “RunOnce” key in the Registry
We’re also investigating the use by Avos of a Linux ransomware component that targets VMware ESXi hypervisor servers by killing any virtual machines, then encrypting the VM files.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RaaS ransomware that reboots systems into Safe Mode to run encryption and attempts to disable security software.
Ransomware family that disables security tools, uses batch scripts and RunOnce registry keys for fileless execution, reboots victims into Safe Mode with Networking to evade endpoint protections, installs AnyDesk for remote access in Safe Mode, and also has a Linux component targeting VMware ESXi by terminating VMs and encrypting VM files.
Ransomware used by attackers who reboot machines into Safe Mode, run AnyDesk, and leverage PDQ Deploy to push batch scripts that deploy the Avos Locker ransomware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.