Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware AvosLocker

AvosLocker

TLP:CLEAR
Family

AI Analysis

· 21 hours ago

Executive Summary

AvosLocker is an aggressively distributed ransomware-as-a-service that encrypts files on both Windows and Linux systems. The malware’s modular delivery and cross‑platform persistence mechanisms have allowed it to target financial services and critical infrastructure worldwide since mid‑2021. Rapidly escalating incidents across 15 countries indicate a high operational risk for organizations handling sensitive data.

Enhanced Description

AvosLocker is a modern ransomware that has been packaged and distributed through the Ransomware-as-a-Service (RaaS) model. Developed in C++, it first surfaced publicly in June 2021, targeting a wide spectrum of sectors including financial services, critical manufacturing, and government facilities across the United States and overseas. The attackers leverage a sophisticated two‑stage delivery mechanism: an initial dropper that installs backdoors on compromised hosts, followed by a modular encryption engine that supports both Windows and Linux file systems. Once executed, AvosLocker scans for high‑value data directories, encrypts recovered files with a robust symmetric cipher, and appends its own ransomware signature to the encrypted filenames. The malware also attempts to evade detection by deleting or obscuring log entries on compromised machines. After the encryption process completes, a ransom notice instructing victims to transfer payment via cryptocurrency is displayed. Despite being distributed as an RaaS product, AvosLocker exhibits operational behaviors that resemble those of bespoke threat actors: it utilizes custom command‑and‑control channels for key delivery and exfiltration, adopts unique file‑extension patterns, and demonstrates cross‑platform persistence tactics in both Windows (e.g., modifying the registry) and Linux (e.g., deploying cron jobs). These characteristics make it a persistent threat to critical infrastructure sectors where downtime is highly costly. The group’s ongoing campaign has reached more than 150 distinct jurisdictions, with confirmed incidents reported in Belgium, Canada, China, Germany, Saudi Arabia, Spain, Syria, Taiwan, Turkey, the United Arab Emirates and the United Kingdom. The malware’s RaaS model lowers the barrier to entry for cybercriminals and expands the potential impact by rapidly scaling operations across diverse geographic regions. The combination of stealthy persistence, cross‑platform encryption capabilities, and broad distribution channels positions AvosLocker as a significant risk to organizations that must safeguard high‑value data, especially in the critical infrastructure domain.

Key Capabilities

  • Cross‑platform file encryption (Windows/Linux) using symmetric cipher
  • Two‑stage delivery with dropper and modular encryption engine
  • Custom command‑and‑control channels for key distribution
  • Persistence via registry manipulation on Windows and cron jobs on Linux
  • File extension alteration to obfuscate encrypted files
  • Log deletion or corruption attempts for stealth

ATT&CK Techniques

T1486
T1053.003
T1078.001

Recommended Actions

  • Disable outbound HTTPS connections to known AvosLocker C&C domains (list from threat feeds)
  • Implement file integrity monitoring to detect unusual file‑extension changes
  • Patch critical OS and application vulnerabilities, particularly those related to privilege escalation
  • Ensure regular backups stored off‑network, verified and tested for restore capability
  • Restrict execution of unsigned binaries at the system level

Suggested Tags

ransomware
RaaS
AvosLocker
Linux
Windows
financial services
critical manufacturing
government facilities
cross‑platform

Confidence Assessment

Confidence in the core facts—such as distribution model, target sectors, cross‑platform support, and geographical reach—is high based on publicly cited investigations. However, granular technical details (e.g., encryption key management, specific persistence hooks) remain less well documented, limiting a full confidence rating for some behavioral assertions.

Description

AvosLocker is ransomware written in C++ that has been offered via the Ransomware-as-a-Service (RaaS) model. It was first observed in June 2021 and has been used against financial services, critical manufacturing, government facilities, and other critical infrastructure sectors in the United States. As of March 2022, AvosLocker had also been used against organizations in Belgium, Canada, China, Germany, Saudi Arabia, Spain, Syria, Taiwan, Turkey, the United Arab Emirates, and the United Kingdom.(Citation: Malwarebytes AvosLocker Jul 2021)(Citation: Trend Micro AvosLocker Apr 2022)(Citation: Joint CSA AvosLocker Mar 2022)

Details

Type
Malware
Platforms
Linux
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.