Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors noescape

Description

NoEscape was a RaaS operation active from May to December 2023 believed to be a rebrand of the defunct Avaddon ransomware, targeting professional services, manufacturing, and healthcare with triple-extortion capabilities (encryption, data theft, and optional DDoS), before abruptly shutting down in an apparent exit scam. Known victims: 126 2 negotiation log(s) available, 3 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 2 months ago

Executive Summary

The NoEscape ransomware operation, believed to be a rebrand of Avaddon, targeted professional services, manufacturing, and healthcare sectors with triple-extortion capabilities from May to December 2023. The group abruptly shut down in an apparent exit scam, but not before compromising 126 organizations. NoEscape's activities highlight the ongoing threat of ransomware operations and the need for vigilance among potential targets.

Goals & Targeting

NoEscape's strategic objectives were centered on achieving financial gain through ransom payments, with a focus on targeting sectors that are likely to have valuable data and a willingness to pay to avoid the consequences of a breach. The group's typical victims were organizations within the professional services, manufacturing, and healthcare sectors, where data confidentiality and availability are critical. By targeting these sectors, NoEscape aimed to maximize its potential returns while minimizing the risks associated with targeting more resilient or well-protected organizations.

Enhanced Description

NoEscape was a medium-sophistication ransomware-as-a-service (RaaS) operation that emerged in May 2023 and was active until December 2023. The group is believed to be a rebrand of the defunct Avaddon ransomware operation, suggesting a level of continuity and potential connections to previous ransomware campaigns. NoEscape's primary motivation was organizational gain, specifically financial gain through ransom payments, and the group employed a triple-extortion model to maximize pressure on its victims.

Key Capabilities

  • Ransomware development and deployment
  • Data exfiltration and extortion
  • DDoS capabilities
  • Negotiation and ransom payment handling
  • Victim profiling and targeting

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1204
T1555

Software / Tooling

Custom ransomware
Data exfiltration tools
DDoS botnets
Virtual private networks (VPNs)

Campaigns & Victims

NoEscape's campaign patterns were characterized by a high volume of attacks against a broad range of targets, with a focus on maximizing financial returns through efficient and effective extortion tactics. The group's operational tempo was marked by a steady stream of attacks throughout its active period, with some variability in terms of targeting and tactics. Notable past operations include the compromise of 126 organizations, with many of these incidents involving triple-extortion tactics and significant ransom demands.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over HTTP/HTTPS using compromised websites
  • Staging infrastructure on virtual private servers (VPS)
  • Data exfiltration via FTP/FTPS

Recommended Actions

  • Implement robust email security controls to prevent spear-phishing attacks
  • Use endpoint detection and response (EDR) tools to detect and block ransomware
  • Conduct regular backups and ensure data availability
  • Implement a incident response plan for ransomware attacks
  • Provide training to employees on recognizing and reporting suspicious activity

Suggested Tags

Ransomware
Criminal
Organizational-gain
Healthcare
Manufacturing
Professional services

Confidence Assessment

The available data provides a moderate level of confidence in the assessment of NoEscape's activities, motivations, and tactics. However, some information gaps exist, particularly regarding the group's internal structure, leadership, and potential connections to other ransomware operations. Further research and analysis are necessary to fully understand the scope and impact of NoEscape's activities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Data Exfiltration
DDoS

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jun 7, 2023
Last Seen
Nov 26, 2023
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.