Avaddon is a ransomware malware targeting Windows systems often spread via malicious spam. The first known attack where Avaddon ransomware was distributed was in February 2020. Avaddon encrypts files using the extension .avdn and uses a TOR payment site for the ransom payment. Known victims: 146 7 negotiation log(s) available, 1 ransom note(s) on file
Objectives
Executive Summary
Avaddon is a medium-sophistication ransomware group targeting Windows systems primarily through malicious spam campaigns. Their primary motivation is financial gain, achieved by encrypting victim files and directing them to pay ransoms via the TOR network. Avaddon first emerged in February 2021 and has targeted numerous victims across various sectors.
Goals & Targeting
Avaddon's strategic objectives revolve around maximizing financial gain through rapid and effective ransomware deployments. The group primarily targets sectors where data breaches or system disruptions can lead to substantial financial losses, such as healthcare, education, and small businesses. Their targeting profile is broad but often focuses on organizations with less mature cybersecurity defenses, making them more likely to pay ransoms. The lack of specific sectoral or geographic targeting suggests a generalized approach, with potential shifts based on operational success.
Enhanced Description
Avaddon is a ransomware group known for targeting Windows-based systems through malicious email campaigns. The group's operations are characterized by the encryption of victim files with the '.avdn' extension, followed by demands for payment via a TOR network site. First identified in February 2021 and last observed in September 2021, Avaddon has demonstrated intermediate sophistication, focusing on financial gain through its ransomware activities. The group's tactics include distributing malicious email attachments or links that lead to the deployment of their ransomware. Despite their relatively short operational timeline, they have affected a significant number of victims, indicating a potential shift in their targeting strategies over time.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Avaddon's campaigns exhibit a rapid deployment cycle, with victims primarily targeted through email-based attacks. Their operations between February 2021 and September 2021 suggest an active but not overly prolonged threat window. The group has demonstrated the ability to adapt their tactics based on victim responses, leveraging encryption and secure payment channels to facilitate ransom collection efficiently.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
This assessment of Avaddon is based on moderate confidence due to limited detailed information available. While their operational timeline, targeting methods, and ransomware mechanics are understood, specific campaign patterns and geographic or sectoral targeting remain unclear. Additional data on Indicators of Compromise (IoCs) would enhance the understanding of their attack vectors.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics