ATT&CKSoftwareAvosLocker

AvosLocker

S1053

Malware.View on attack.mitre.org

About this malware

AvosLocker is ransomware written in C++ that has been offered via the Ransomware-as-a-Service (RaaS) model. It was first observed in June 2021 and has been used against financial services, critical manufacturing, government facilities, and other critical infrastructure sectors in the United States. As of March 2022, AvosLocker had also been used against organizations in Belgium, Canada, China, Germany, Saudi Arabia, Spain, Syria, Taiwan, Turkey, the United Arab Emirates, and the United Kingdom.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1027
Obfuscated Files or Information

AvosLocker has used XOR-encoded strings.

T1027.007
Dynamic API Resolution

AvosLocker has used obfuscated API calls that are retrieved by their checksums.

T1036.008
Masquerade File Type

AvosLocker has been disguised as a .jpg file.

T1057
Process Discovery

AvosLocker has discovered system processes by calling `RmGetList`.

T1083
File and Directory Discovery

AvosLocker has searched for files and directories on a compromised network.

T1106
Native API

AvosLocker has used a variety of Windows API calls, including `NtCurrentPeb` and `GetLogicalDrives`.

T1124
System Time Discovery

AvosLocker has checked the system time before and after encryption.

T1135
Network Share Discovery

AvosLocker has enumerated shared drives on a compromised network.

T1140
Deobfuscate/Decode Files or Information

AvosLocker has deobfuscated XOR-encoded strings.

T1486
Data Encrypted for Impact

AvosLocker has encrypted files and network resources using AES-256 and added an `.avos`, `.avos2`, or `.AvosLinux` extension to filenames.

T1489
Service Stop

AvosLocker has terminated specific processes before encryption.

T1529
System Shutdown/Reboot

AvosLocker’s Linux variant has terminated ESXi virtual machines.

T1547.001
Registry Run Keys / Startup Folder

AvosLocker has been executed via the `RunOnce` Registry key to run itself on safe mode.

T1564.003
Hidden Window

AvosLocker has hidden its console window by using the `ShowWindow` API function.

T1688
Safe Mode Boot

AvosLocker can restart a compromised machine in safe mode.

Groups that use it0

None recorded.

Campaigns1

References3

  1. Joint CSA AvosLocker Mar 2022 Open source
    FBI, FinCEN, Treasury. (2022, March 17). Indicators of Compromise Associated with AvosLocker Ransomware. Retrieved January 11, 2023.
  2. Malwarebytes AvosLocker Jul 2021 Open source
    Hasherezade. (2021, July 23). AvosLocker enters the ransomware scene, asks for partners. Retrieved January 11, 2023.
  3. Trend Micro AvosLocker Apr 2022 Open source
    Trend Micro Research. (2022, April 4). Ransomware Spotlight AvosLocker. Retrieved January 11, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.