Avaddon Ransomware

Description Summary

Avaddon is a ransomware malware targeting Windows systems often spread via malicious spam. The first known attack where Avaddon ransomware was distributed was in February 2020. Avaddon encrypts files using the extension .avdn and uses a TOR payment site for the ransom payment.

Threat Actor

Russian-speaking RaaS; spread via malicious spam (Phorpiex). Released all decryption keys on shutdown.

Technical Indicators

Encryption Extension
.avdn
Encryption Algorithm
AES-256 (files) + RSA-2048 (key wrapping)
Ransom Note Name
[ID]-readme.html / readme.txt
Targeted Industries
Cross-sector (manufacturing, healthcare, education)
First Seen
February 2020
Last Seen
June 2021 (shut down; released decryption keys)
Geographical Location
Worldwide

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
Exfiltration x 1 T1567 Exfiltration Over Web Service (leak site)
Initial Access x 2 T1190 Exploit Public-Facing Application
T1078 Valid Accounts