Avaddon

S0640

Malware.View on attack.mitre.org

About this malware

Avaddon is ransomware written in C++ that has been offered as Ransomware-as-a-Service (RaaS) since at least June 2020.

Techniques used17

Procedure examples17

TechniqueProcedure example
T1016
System Network Configuration Discovery

Avaddon can collect the external IP address of the victim.

T1027
Obfuscated Files or Information

Avaddon has used encrypted strings.

T1047
Windows Management Instrumentation

Avaddon uses wmic.exe to delete shadow copies.

T1057
Process Discovery

Avaddon has collected information about running processes.

T1059.007
JavaScript

Avaddon has been executed through a malicious JScript downloader.

T1083
File and Directory Discovery

Avaddon has searched for specific files prior to encryption.

T1106
Native API

Avaddon has used the Windows Crypto API to generate an AES key.

T1112
Modify Registry

Avaddon modifies several registry keys for persistence and UAC bypass.

T1135
Network Share Discovery

Avaddon has enumerated shared folders and mapped volumes.

T1140
Deobfuscate/Decode Files or Information

Avaddon has decrypted encrypted strings.

T1486
Data Encrypted for Impact

Avaddon encrypts the victim system using a combination of AES256 and RSA encryption schemes.

T1489
Service Stop

Avaddon looks for and attempts to stop database processes.

T1490
Inhibit System Recovery

Avaddon deletes backups and shadow copies using native system tools.

T1547.001
Registry Run Keys / Startup Folder

Avaddon uses registry run keys for persistence.

T1548.002
Bypass User Account Control

Avaddon bypasses UAC using the CMSTPLUA COM interface.

View all 17 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. Arxiv Avaddon Feb 2021 Open source
    Yuste, J. Pastrana, S. (2021, February 9). Avaddon ransomware: an in-depth analysis and decryption of infected systems. Retrieved August 19, 2021.
  2. Awake Security Avaddon Open source
    Gahlot, A. (n.d.). Threat Hunting for Avaddon Ransomware. Retrieved August 19, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.