Avaddon was a ransomware group that emerged in early 2019, transitioning to a Ransomware-as-a-Service (RaaS) model by June 2020, actively recruiting affiliates on Russian-speaking forums. The group's primary motivation was financial gain, which they pursued through a double extortion strategy involving both data encryption and the threat of public release of stolen information. A defining characteristic of Avaddon was its operational rule against targeting organizations within the Commonwealth of Independent States (CIS) countries, a policy often implemented by Russian-speaking cybercriminal groups. In early 2021, Avaddon further escalated its pressure tactics by incorporating Distributed Denial of Service (DDoS) attacks against non-compliant victims. The group publicly ceased all operations in June 2021, subsequently releasing decryption keys for affected organizations.
Tecnicas MITRE
T1471, T1036, T1090, T1486, T1071, T1566
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
United Arab EmiratesAustraliaBelgiumBermudaBrazilCanadaSwitzerlandChileChinaColombia
Sectores objetivo (SOCRadar)
Construction of BuildingsFood ManufacturingOther Information ServicesMonetary Authorities-Central BankCredit UnionsRail TransportationSoftware PublishersReal EstateEnterprises & HoldingAccommodation