Avos is the threat actor group behind AvosLocker ransomware, a RaaS operation active since June 2021 that recruited affiliates to deploy ransomware against critical infrastructure including financial services, manufacturing, and government sectors across the US and a dozen other countries. 1 negotiation log(s) available
Objectives
Executive Summary
Avos is a medium-sophistication criminal threat actor group operating since June 2021, primarily involved in ransomware activities through AvosLocker. They employ a Ransomware as a Service (RaaS) model, recruiting affiliates to target critical infrastructure across the financial, manufacturing, and government sectors globally. Their operations focus on generating financial gains via ransom payments.
Goals & Targeting
Avos operates with the strategic goal of generating profits through ransomware attacks. Their targeting strategy focuses on sectors where data breaches or system downtimes can lead to substantial financial repercussions. This includes critical infrastructure in finance, manufacturing, and government, which are also less likely to publicize breaches due to potential reputational damage.
Enhanced Description
Avos is known for their AvosLocker ransomware, which they distribute through a RaaS operation. This group has targeted industries critical to national safety, including financial services, manufacturing, and government sectors in the US and various other countries. Their use of affiliates suggests a franchise-like model, allowing multiple actors to deploy their ransomware in exchange for a share of proceeds. The group's primary objective is financial gain through successful ransomware deployments, which have caused significant disruptions and monetary losses for affected organizations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Avos has been active for over a year, targeting critical sectors with significant geographic reach. Their campaigns likely involve high operational tempo due to their RaaS model, allowing frequent attacks through different affiliates. Notable operations may include incidents against US financial institutions and European manufacturing.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in the general operational model of Avos, with areas of uncertainty regarding specific TTPs and exact campaign details. Additional intelligence sharing could enhance knowledge of their tools and attack patterns.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
4
IOCs
0
Observed Data
0
Tactics