According to Crowdstrike, RIDDLE SPIDER is the operator behind the avaddon ransomware
Executive Summary
RIDDLE SPIDER is a threat actor associated with the Avaddon ransomware family, which employs double extortion tactics. The group primarily targets healthcare, education, and other sectors globally, leveraging sophisticated techniques to breach organizations and encrypt sensitive data for financial gain.
Goals & Targeting
RIDDLE SPIDER's strategic objectives are centered around financial gain through ransomware deployments. The group primarily targets sectors with high data sensitivity and recovery costs, such as healthcare and education, where the impact of disruptions can be severe. RIDDLE SPIDER's global reach suggests a focus on broad geographic targeting to maximize victim pools.
Enhanced Description
RIDDLE SPIDER operates as a high-sophistication cybercriminal group responsible for deploying the Avaddon ransomware. This actor is known for its ability to disrupt operations by encrypting critical systems and demanding substantial ransoms, often threatening to release stolen data unless paid. The group's activities demonstrate a clear focus on maximizing financial gain through targeted ransom campaigns. RIDDLE SPIDER's operations highlight the evolving nature of ransomware attacks, where threat actors increasingly adopt professionalized tactics and tools to breach defenses and extort victims.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
RIDDLE SPIDER's campaigns demonstrate a focus on sectors with high recovery costs and data sensitivity. The group has been observed targeting healthcare organizations globally, causing significant disruptions. Notable operations include large-scale ransomware deployments that have resulted in data leaks and financial losses for victims. Campaign patterns indicate a preference for double extortion tactics, where encrypted data is also exfiltrated and released unless ransoms are paid.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in RIDDLE SPIDER's TTPs and capabilities is high due to the detailed analysis of Avaddon ransomware campaigns by CrowdStrike. However, gaps exist regarding specific toolsets beyond Avaddon and exact targeting patterns outside healthcare.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics