Description Summary
Avaddon is a ransomware malware targeting Windows systems often spread via malicious spam. The first known attack where Avaddon ransomware was distributed was in February 2020. Avaddon encrypts files using the extension .avdn and uses a TOR payment site for the ransom payment.
Threat Actor
Russian-speaking RaaS; spread via malicious spam (Phorpiex). Released all decryption keys on shutdown.
Technical Indicators
Encryption Extension
.avdn
Encryption Algorithm
AES-256 (files) + RSA-2048 (key wrapping)
Ransom Note Name
[ID]-readme.html / readme.txt
Targeted Industries
Cross-sector (manufacturing, healthcare, education)
First Seen
February 2020
Last Seen
June 2021 (shut down; released decryption keys)
Geographical Location
Worldwide
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Impact x 2 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| Exfiltration x 1 | T1567 | Exfiltration Over Web Service (leak site) |
| Initial Access x 2 | T1190 | Exploit Public-Facing Application |
| T1078 | Valid Accounts |