Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors avaddon

Description

Avaddon is a ransomware malware targeting Windows systems often spread via malicious spam. The first known attack where Avaddon ransomware was distributed was in February 2020. Avaddon encrypts files using the extension .avdn and uses a TOR payment site for the ransom payment. Known victims: 146 7 negotiation log(s) available, 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 2 weeks ago

Executive Summary

Avaddon is a medium-sophistication ransomware group targeting Windows systems primarily through malicious spam campaigns. Their primary motivation is financial gain, achieved by encrypting victim files and directing them to pay ransoms via the TOR network. Avaddon first emerged in February 2021 and has targeted numerous victims across various sectors.

Goals & Targeting

Avaddon's strategic objectives revolve around maximizing financial gain through rapid and effective ransomware deployments. The group primarily targets sectors where data breaches or system disruptions can lead to substantial financial losses, such as healthcare, education, and small businesses. Their targeting profile is broad but often focuses on organizations with less mature cybersecurity defenses, making them more likely to pay ransoms. The lack of specific sectoral or geographic targeting suggests a generalized approach, with potential shifts based on operational success.

Enhanced Description

Avaddon is a ransomware group known for targeting Windows-based systems through malicious email campaigns. The group's operations are characterized by the encryption of victim files with the '.avdn' extension, followed by demands for payment via a TOR network site. First identified in February 2021 and last observed in September 2021, Avaddon has demonstrated intermediate sophistication, focusing on financial gain through its ransomware activities. The group's tactics include distributing malicious email attachments or links that lead to the deployment of their ransomware. Despite their relatively short operational timeline, they have affected a significant number of victims, indicating a potential shift in their targeting strategies over time.

Key Capabilities

  • Ransomware distribution via malicious email campaigns
  • Usage of TOR for payment transactions
  • Encryption of files with .avdn extension

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Credential Access

ATT&CK Techniques

T1566.002 (Spear-phishing via email)
T1574.005 (Ransomware)

Software / Tooling

Avaddon Ransomware
Phishing Email Tools

Campaigns & Victims

Avaddon's campaigns exhibit a rapid deployment cycle, with victims primarily targeted through email-based attacks. Their operations between February 2021 and September 2021 suggest an active but not overly prolonged threat window. The group has demonstrated the ability to adapt their tactics based on victim responses, leveraging encryption and secure payment channels to facilitate ransom collection efficiently.

IOC Patterns

  • Phishing emails with malicious links
  • Encrypted files ending in .avdn
  • TOR network traffic related to Avaddon

Recommended Actions

  • Implement rigorous email filtering solutions
  • Enhance endpoint detection and response (EDR) capabilities
  • Regularly back up critical systems and test recovery processes
  • Monitor for suspicious file activities and network anomalies

Suggested Tags

Ransomware
Financial-Motivation
Medium-Sophistication

Confidence Assessment

This assessment of Avaddon is based on moderate confidence due to limited detailed information available. While their operational timeline, targeting methods, and ransomware mechanics are understood, specific campaign patterns and geographic or sectoral targeting remain unclear. Additional data on Indicators of Compromise (IoCs) would enhance the understanding of their attack vectors.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financial-Motivation
Medium-Sophistication

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Feb 1, 2021
Last Seen
Sep 9, 2021
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.