Advisor

Avaddon

2 min read
Jump to:

Summary

Avaddon is a ransomware-as-a-service (RaaS) operation that emerged in early 2020, targeting organizations worldwide by encrypting data and demanding ransom payments for decryption keys. It is known for employing double extortion tactics, where attackers not only encrypt victims’ files but also exfiltrate sensitive data to threaten public release if ransoms are not paid. Avaddon has been distributed through phishing campaigns, exploit kits, and compromised remote desktop protocols (RDP).

Key Characteristics

  • Operates as a ransomware-as-a-service model, allowing affiliates to deploy the ransomware in exchange for a share of the ransom payments.
  • Utilizes double extortion by combining data encryption with data theft and subsequent threats to leak stolen information.
  • Targets a wide range of sectors including healthcare, finance, education, and government entities.
  • Employs various infection vectors such as phishing emails, malicious attachments, exploit kits, and brute-force attacks on RDP.
  • Uses strong encryption algorithms to lock victim files, making recovery without the decryption key difficult.
  • Maintains a public leak site on the dark web to pressure victims into paying ransoms.
  • Disappeared from the public scene in mid-2021 following law enforcement actions but remains a notable example of RaaS threats.

Defensive Controls

  • Implement robust email filtering and phishing awareness training to reduce the risk of initial infection.
  • Enforce strong password policies and multi-factor authentication, especially for remote access services like RDP.
  • Regularly update and patch software and systems to mitigate vulnerabilities exploited by ransomware.
  • Maintain offline and encrypted backups of critical data to enable recovery without paying ransom.
  • Deploy endpoint detection and response (EDR) solutions to identify and contain ransomware activity.
  • Monitor network traffic for unusual data exfiltration or communication with known ransomware command and control servers.
  • Establish and test incident response plans specific to ransomware attacks.

Related Security Solutions

Security solutions relevant to defending against Avaddon ransomware include advanced email security gateways, endpoint protection platforms with anti-ransomware capabilities, network intrusion detection systems, vulnerability management tools, and secure backup and recovery solutions. Additionally, threat intelligence services that track ransomware groups and their infrastructure can aid in proactive defense and incident response.

Tags: Application Attacks Avaddon Cybersecurity Data Exfiltration double extortion endpoint protection Phishing ransomware ransomware-as-a-service remote desktop protocol threat intelligence