avoslocker logo

avoslocker

2 incidentes 1 paises 1 sectores ransomware Ultimo: 2026-06-25
Aliases: Avos
Ver en IntelTracker → APTTrail →
AvosLocker is a ransomware-as-a-service (RaaS) group that emerged in mid-2021, recruiting affiliates to deploy its ransomware. The group is financially motivated, employing a double-extortion model where they encrypt victim files and exfiltrate data, threatening to leak or auction it on their dedicated Tor-based leak sites if ransom demands are not met. What distinguishes AvosLocker is its tactic of restarting victim machines into safe mode to bypass security defenses, and its unique approach to monetize stolen data through an auctioning system. While not as prominent as some other major ransomware groups, AvosLocker has continuously evolved its operations, expanding from primarily targeting Windows systems to include Linux and VMware ESXi environments.
Tecnicas MITRE
T1095, T1555, T1070, T1102, T1090, T1036
CVEs relacionadas
CVE-2021-34523, CVE-2021-34473, CVE-2021-31207

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

United Arab EmiratesArgentinaAustriaAustraliaBelgiumBrazilCanadaSwitzerlandChinaColombia

Sectores atacados

Healthcare (1)

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesCredit UnionsSoftware PublishersReal EstateHospitalsAccommodationManufacturingConstruction

URLs nuevas detectadas en IntelTracker

github.com ransomware.anggipradana.com

Victimas (1)

Ransom Notes: avoslocker (1 notes from ThreatLabz)18 Jun 2026
Report
avoslocker - Ransom NotesEste grupo de ransomware tiene 1 notas de rescate documentadas en el repositorio ThreatLabz/ransomware_notes. Las notas de re…