Ransomware Group intelligence
Avaddon
InactiveTrack Avaddon with 146 published victims and 1 known leak locations in a single intelligence view.
Overview
Avaddon is tracked by Breach House as a ransomware group with 146 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 2h ago | avaddongun7rngel.onion |
Top Activity Sectors (17)
- Not identified 65
- Services 25
- Finance / Legal / Insurance 9
- Communication / Marketing 7
- IT 7
- Manufacturing / Engineering 6
- Healthcare / Pharma 6
- Transportation / Travel / Logistics 4
- Energy 4
- Public Sector 3
- Construction / Real Estate 2
- Agriculture / Food 2
- Retail / E-commerce 2
- Telecommunications 1
- Hospitality / Food & Beverage / Tourism 1
- Education 1
- NGOs / Associations 1
Typical Attacks (17)
▼How Avaddon typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Avaddon.
-
T1047 Windows Management Instrumentation Execution
What they do: Avaddon uses wmic.exe to delete shadow copies.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.007 JavaScript Execution
What they do: Avaddon has been executed through a malicious JScript downloader.
What that means: Adversaries may abuse various implementations of JavaScript for execution.
-
T1106 Native API Execution
What they do: Avaddon has used the Windows Crypto API to generate an AES key.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: Avaddon modifies several registry keys for persistence and UAC bypass.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: Avaddon uses registry run keys for persistence.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1548.002 Bypass User Account Control Privilege Escalation
What they do: Avaddon bypasses UAC using the CMSTPLUA COM interface.
What that means: Adversaries may bypass UAC mechanisms to elevate process privileges on system.
-
T1027 Obfuscated Files or Information Stealth
What they do: Avaddon has used encrypted strings.
What that means: Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: Avaddon has decrypted encrypted strings.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Avaddon looks for and attempts to stop anti-malware solutions.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1016 System Network Configuration Discovery Discovery
What they do: Avaddon can collect the external IP address of the victim.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1057 Process Discovery Discovery
What they do: Avaddon has collected information about running processes.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1083 File and Directory Discovery Discovery
What they do: Avaddon has searched for specific files prior to encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1135 Network Share Discovery Discovery
What they do: Avaddon has enumerated shared folders and mapped volumes.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1614.001 System Language Discovery Discovery
What they do: Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities.
What that means: Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host.
-
T1486 Data Encrypted for Impact Impact
What they do: Avaddon encrypts the victim system using a combination of AES256 and RSA encryption schemes.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Avaddon looks for and attempts to stop database processes.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Avaddon deletes backups and shadow copies using native system tools.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (12)
▼Software Avaddon has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery & enumeration
Exfiltration
Offensive security tooling
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Crypto Wallets (1)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
bc1q65f238kv6gc235smuzcehshxcqljn2g7l5sz7j |
bitcoin | $1,185 | 1 |
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
avaddon.txt
-------=== Your network has been infected! ===-------
***************** DO NOT DELETE THIS FILE UNTIL ALL YOUR DATA HAVE BEEN RECOVERED *****************
All your documents, photos, databases and other important files have been encrypted and have the extension: {{ext}}
You are not able to decrypt it by yourself. But don't worry, we can help you to restore all your files!
The only way to restore your files is to buy our special software. Only we can give you this software and only we can restore your files!
We have also downloaded a lot of private data from your network.
If you do not contact as in a 3 days we will post information about your breach on our public news website (avaddongun7rngel.onion) and after 7 days the whole downloaded info.
You can get more information on our page, which is located in a Tor hidden network.
How to get to our page
--------------------------------------------------------------------------------
|
| 1. Download Tor browser - https://www.torproject.org/
|
| 2. Install Tor browser
|
| 3. Open link in Tor browser - avaddonbotrxmuyl.onion
|
| 4. Follow the instructions on this page
|
--------------------------------------------------------------------------------
Your ID:
--------------------------------------------------------------------------------
{{id}}
--------------------------------------------------------------------------------
* DO NOT TRY TO RECOVER FILES YOURSELF!
* DO NOT MODIFY ENCRYPTED FILES!
* * * OTHERWISE, YOU MAY LOSE ALL YOUR FILES FOREVER! * * *
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (146)
Search, filter and paginate the victim timeline for Avaddon. Showing 1–100 of 146.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | EFCO forms id855 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Sky Leasing, LLC id854 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Golden Aluminum id853 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | J.C. Cannistraro id852 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Lonrho id851 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | American Bank Systems INC id850 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Brown Robert LLP id849 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | National AIDS Control Council id848 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Monterey Bay Air Resources District id847 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Dade City Florida id846 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | KOE id845 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | AHT Global id844 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Garvin Promotion Group, LLC id843 View details | United States | Communication / Marketing | — | |
|
No additional victim description available. |
|||||
| Ransomware | NetVigour Inc id842 View details | United States | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Intensive Care On-Line Network , Inc id841 View details | Telecommunications | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Payzant Building Products Ltd id840 View details | Construction / Real Estate | — | ||
|
No additional victim description available. |
|||||
| Ransomware | International Longshore & Warehouse Union id839 View details | Transportation / Travel / Logistics | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Marolles-en-Brie id838 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Finalyse id837 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | BIOREP TECHNOLOGIES, INC. id836 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MK-Technik id835 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Allanasons Ltd id834 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | American Heart of Poland Inc id833 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | PT Asuransi Bintang Tbk id832 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | VAUGHN CONCRETE PRODUCTS, INC id831 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Groupe Qualinet Inc. id830 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Somerset ISD id829 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | FBL Advogados id828 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Hardy Buoys Smoked Fish Inc. id827 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | KEITH MACHINERY CORP. id826 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | BEE LINE LOGISTICS, INC id825 View details | Transportation / Travel / Logistics | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Elite Software Inc id824 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MundoFertil id823 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SVI ASSURANCES id822 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | UNIVERSAL ACCOUNTING SERVICES INC id821 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | The Capital Medical Center id820 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Mullins Food Products Inc id819 View details | Agriculture / Food | — | ||
|
No additional victim description available. |
|||||
| Ransomware | JFC International (Europe) id818 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Carnegie Wave Energy id817 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Grand Power Systems id816 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | VERIHA TRUCKING INC id815 View details | Transportation / Travel / Logistics | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Party Rental LTD id814 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Prefeitura Municipal de Saquarema id813 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CELL Foods Inc. id812 View details | Agriculture / Food | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CASHMAG id811 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Doré Law Group P.C id810 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Omni Manufacturing, Inc. id809 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | FUTURIMPLANTS id808 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ANLEC R&D id807 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | La compagnie du SAV id806 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SISCONT id805 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | AlohaABA id804 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Zhuhai Languan Electronic Technology Co., Ltd id803 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Schneider & Branch id802 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Mikro Trading id801 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Basque Center for Applied Mathematics-BCAM id800 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Targetcom id799 View details | Retail / E-commerce | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Steel Art Signs Corp. id798 View details | Canada | Manufacturing / Engineering | — | |
|
No additional victim description available. |
|||||
| Ransomware | BRIDGEWAY SENIOR HEALTHCARE id797 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SOVRIN PLASTICS LIMITED id796 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Millwright Regional Council of Ontario id795 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Gorzynski id794 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ALIZON id793 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CERINNOV, UNIPESSOAL, LDA id792 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | BDhouse id791 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Indonesia Infrastructure Guarantee Fund id790 View details | Construction / Real Estate | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Município de Constância id789 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Grupo Prilux id788 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Cambridge Weight Plan Ltd id787 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ASBIS CZ, spol. s r.o. id786 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | HealthCare Global Enterprises Ltd id785 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MITCHAM INDUSTRIES INC id784 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | B.W. Wilson Paper id783 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Aldes id782 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Coburn Supply Company , Inc. id781 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | DBMSC Steel id780 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | EROWA LTD id779 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Logixal id778 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Dicon Fiberoptics Inc id777 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | BIANCHI VENDING id776 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Exedy Corporation id775 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Active Business & Technology id774 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MSPharma id773 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Hames Homes LLC id772 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Greatwide Truckload id771 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CJ Selecta S/A id770 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ADUANAS Y SERVICIOS FORNESA SL id769 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Innovative Office Solutions LLC id768 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Partit Nazzjonalista id767 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Cathar Games id766 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | OLOMOUC id765 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MUNICIPIO DE QUATRO BARRAS id764 View details | Hospitality / Food & Beverage / Tourism | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Newcomb Secondary College id763 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | COMUNE DI VILLAFRANCA D'ASTI id762 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CNE id761 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Farrells id760 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SC TECHNOSEAL SERVICES SRL id759 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MEDUNA vakuová kalírna s.r.o id758 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Construct id757 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Diacom id756 View details | Other | — | ||
|
No additional victim description available. |
|||||