ATT&CKReferencesHornet Security Avaddon June 2020

Hornet Security Avaddon June 2020

Security Lab. (2020, June 5). Avaddon: From seeking affiliates to in-the-wild in 2 days. Retrieved August 19, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
MalwareAvaddon

Avaddon uses wmic.exe to delete shadow copies.

T1059.007
JavaScript
MalwareAvaddon

Avaddon has been executed through a malicious JScript downloader.

T1106
Native API
MalwareAvaddon

Avaddon has used the Windows Crypto API to generate an AES key.

T1490
Inhibit System Recovery
MalwareAvaddon

Avaddon deletes backups and shadow copies using native system tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.