avos logo

avos

1 incidentes 1 paises 1 sectores ransomware RU Ultimo: 2026-06-25
Aliases: AvosLocker
Ver en IntelTracker → APTTrail →
Avos, also known as AvosLocker, is a financially motivated ransomware-as-a-service (RaaS) group that first emerged in June 2021. Operating as an affiliate-based model, AvosLocker quickly established itself by offering a profit-sharing scheme to cybercriminals, where the core operators handle negotiations and data leaks. The group initially focused on Windows systems but expanded its capabilities to include Linux variants, notably targeting VMware ESXi environments. A distinguishing characteristic of AvosLocker is its aggressive double extortion strategy, which involves not only encrypting victim data but also exfiltrating it and threatening to publish it on a dedicated leak site. The group has been observed making direct phone calls to victims and, in some instances, threatening Distributed Denial of Service (DDoS) attacks to compel ransom payment. This tactic of directly engaging and pressuring victims sets it apart from many other RaaS operations.
Tecnicas MITRE
T1071.001, T1486, T1569.002, T1059.001

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

United Arab EmiratesArgentinaAustriaAustraliaBelgiumBrazilCanadaSwitzerlandChileChina

Sectores atacados

Government (1)

Sectores objetivo (SOCRadar)

Food ManufacturingOther Information ServicesSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationManufacturingConstructionElectrical Equipment, Appliance, and Component Manufacturing

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com