Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Avos is the threat actor group behind AvosLocker ransomware, a RaaS operation active since June 2021 that recruited affiliates to deploy ransomware against critical infrastructure including financial services, manufacturing, and government sectors across the US and a dozen other countries. 1 negotiation log(s) available

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Avos is a medium-sophistication criminal threat actor group operating since June 2021, primarily involved in ransomware activities through AvosLocker. They employ a Ransomware as a Service (RaaS) model, recruiting affiliates to target critical infrastructure across the financial, manufacturing, and government sectors globally. Their operations focus on generating financial gains via ransom payments.

Goals & Targeting

Avos operates with the strategic goal of generating profits through ransomware attacks. Their targeting strategy focuses on sectors where data breaches or system downtimes can lead to substantial financial repercussions. This includes critical infrastructure in finance, manufacturing, and government, which are also less likely to publicize breaches due to potential reputational damage.

Enhanced Description

Avos is known for their AvosLocker ransomware, which they distribute through a RaaS operation. This group has targeted industries critical to national safety, including financial services, manufacturing, and government sectors in the US and various other countries. Their use of affiliates suggests a franchise-like model, allowing multiple actors to deploy their ransomware in exchange for a share of proceeds. The group's primary objective is financial gain through successful ransomware deployments, which have caused significant disruptions and monetary losses for affected organizations.

Key Capabilities

  • Ransomware deployment
  • Affiliate recruitment model
  • Targeting of critical infrastructure
  • Operation through RaaS

MITRE ATT&CK Tactics

Persistence
Credential Access
Lateral Movement
Destruction

ATT&CK Techniques

T1059.003
T1078.001
T1021.004
T1566.002

Software / Tooling

AvosLocker ransomware
Cobalt Strike (Potential TTPs)

Campaigns & Victims

Avos has been active for over a year, targeting critical sectors with significant geographic reach. Their campaigns likely involve high operational tempo due to their RaaS model, allowing frequent attacks through different affiliates. Notable operations may include incidents against US financial institutions and European manufacturing.

IOC Patterns

  • Spear-phishing emails with malicious links
  • Lateral movement across networks
  • File encryption patterns indicative of ransomware

Recommended Actions

  • Implement network monitoring for signs of lateral movement
  • Enhance email filtering to detect phishing attempts
  • Regularly patch systems against known vulnerabilities
  • Secure backups to protect against ransomware encryption

Suggested Tags

ransomware
financial-sector
critical-infrastructure

Confidence Assessment

Moderate confidence in the general operational model of Avos, with areas of uncertainty regarding specific TTPs and exact campaign details. Additional intelligence sharing could enhance knowledge of their tools and attack patterns.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

4

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
Government Targeting
ransomware
financial-sector
critical-infrastructure

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.