Ransomware Group intelligence
Avaddon
InactiveTrack Avaddon with 146 published victims and 1 known leak locations in a single intelligence view.
Overview
Avaddon is tracked by Breach House as a ransomware group with 146 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 2h ago | avaddongun7rngel.onion |
Top Activity Sectors (17)
- Not identified 65
- Services 25
- Finance / Legal / Insurance 9
- Communication / Marketing 7
- IT 7
- Manufacturing / Engineering 6
- Healthcare / Pharma 6
- Transportation / Travel / Logistics 4
- Energy 4
- Public Sector 3
- Construction / Real Estate 2
- Agriculture / Food 2
- Retail / E-commerce 2
- Telecommunications 1
- Hospitality / Food & Beverage / Tourism 1
- Education 1
- NGOs / Associations 1
Typical Attacks (17)
▼How Avaddon typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Avaddon.
-
T1047 Windows Management Instrumentation Execution
What they do: Avaddon uses wmic.exe to delete shadow copies.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.007 JavaScript Execution
What they do: Avaddon has been executed through a malicious JScript downloader.
What that means: Adversaries may abuse various implementations of JavaScript for execution.
-
T1106 Native API Execution
What they do: Avaddon has used the Windows Crypto API to generate an AES key.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: Avaddon modifies several registry keys for persistence and UAC bypass.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: Avaddon uses registry run keys for persistence.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1548.002 Bypass User Account Control Privilege Escalation
What they do: Avaddon bypasses UAC using the CMSTPLUA COM interface.
What that means: Adversaries may bypass UAC mechanisms to elevate process privileges on system.
-
T1027 Obfuscated Files or Information Stealth
What they do: Avaddon has used encrypted strings.
What that means: Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: Avaddon has decrypted encrypted strings.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Avaddon looks for and attempts to stop anti-malware solutions.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1016 System Network Configuration Discovery Discovery
What they do: Avaddon can collect the external IP address of the victim.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1057 Process Discovery Discovery
What they do: Avaddon has collected information about running processes.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1083 File and Directory Discovery Discovery
What they do: Avaddon has searched for specific files prior to encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1135 Network Share Discovery Discovery
What they do: Avaddon has enumerated shared folders and mapped volumes.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1614.001 System Language Discovery Discovery
What they do: Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities.
What that means: Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host.
-
T1486 Data Encrypted for Impact Impact
What they do: Avaddon encrypts the victim system using a combination of AES256 and RSA encryption schemes.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Avaddon looks for and attempts to stop database processes.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Avaddon deletes backups and shadow copies using native system tools.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (12)
▼Software Avaddon has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery & enumeration
Exfiltration
Offensive security tooling
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Crypto Wallets (1)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
bc1q65f238kv6gc235smuzcehshxcqljn2g7l5sz7j |
bitcoin | $1,185 | 1 |
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
avaddon.txt
-------=== Your network has been infected! ===-------
***************** DO NOT DELETE THIS FILE UNTIL ALL YOUR DATA HAVE BEEN RECOVERED *****************
All your documents, photos, databases and other important files have been encrypted and have the extension: {{ext}}
You are not able to decrypt it by yourself. But don't worry, we can help you to restore all your files!
The only way to restore your files is to buy our special software. Only we can give you this software and only we can restore your files!
We have also downloaded a lot of private data from your network.
If you do not contact as in a 3 days we will post information about your breach on our public news website (avaddongun7rngel.onion) and after 7 days the whole downloaded info.
You can get more information on our page, which is located in a Tor hidden network.
How to get to our page
--------------------------------------------------------------------------------
|
| 1. Download Tor browser - https://www.torproject.org/
|
| 2. Install Tor browser
|
| 3. Open link in Tor browser - avaddonbotrxmuyl.onion
|
| 4. Follow the instructions on this page
|
--------------------------------------------------------------------------------
Your ID:
--------------------------------------------------------------------------------
{{id}}
--------------------------------------------------------------------------------
* DO NOT TRY TO RECOVER FILES YOURSELF!
* DO NOT MODIFY ENCRYPTED FILES!
* * * OTHERWISE, YOU MAY LOSE ALL YOUR FILES FOREVER! * * *
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (146)
Search, filter and paginate the victim timeline for Avaddon. Showing 101–146 of 146.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | LG Vina Chemical id755 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Schepisi Communications id754 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | EUROMAIS - PEÇAS E PNEUS, LDA id753 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SPINE & DISC id752 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Cocal id751 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Glasbau Wiedemann GmbH id750 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Cinov Federation id749 View details | NGOs / Associations | — | ||
|
No additional victim description available. |
|||||
| Ransomware | TAIWAN SURFACE MOUNTING TECHNOLOGY CORP. id748 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Coindu id747 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ULTRACEUTICALS PTY LIMITED id746 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | DOCTUM PHARMACEUTICAL Κ. T. YIOKARIS & CO S.A. id745 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MEGAPOLIS HOLDINGS (OVERSEAS) LIMITED id744 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | NIJMAN / ZEETANK International Transport Sp. z o. o. id743 View details | Transportation / Travel / Logistics | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ACER FINANCE id742 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | PT Angkasa Pura I id741 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Henry Oil & Gas id740 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SL Corporation id739 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Letton Percival id738 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Vistex id737 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | EVGA id736 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | AXA Group id735 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | RINGSPANN GmbH id734 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Solvere LLC id733 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | PKMK law&finance s.r.o id732 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | 360 InStore id731 View details | Retail / E-commerce | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Maryan beachwear group GmbH id730 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | JetSJ id729 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Rate Rabbit Inc id728 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Halwani Bros Ltd id727 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Cube Audit Ltd id726 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | FEBANCOLOMBIA id725 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ballas Capital Limited id724 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Servilex Advocaten id723 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Johann Kupp GmbH & Co. KG id722 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Carlos Federspiel & Co SA id721 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Buckeye International Inc id720 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | LE VOLCAN id719 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Syndex id718 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Inventec Appliances Corp id717 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Imperial Printing and Paper Box Mfg id716 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Accounts IQ id715 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Town of Freeport id651 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | AXA (insurance) id613 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Presque Isle Police Department id606 View details | United States | Communication / Marketing | — | |
|
No additional victim description available. |
|||||
| Ransomware | Capital Medical Center id567 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Carnegie Clean Energy id568 View details | Australia | Energy | — | |
|
No additional victim description available. |
|||||