AvosLocker
AvosLocker is a ransomware-as-a-service (RaaS) operation that emerged in June 2021 and is known for double-extortion tactics. Reporting cited in the content says it has targeted entities in the United States, Canada, the United Kingdom, and Spain, with a focus on critical infrastructure. Described initial access vectors include spear-phishing, exploitation of public-facing applications, and compromised RDP credentials. The group has been reported to establish persistence with custom webshells, escalate privileges via credential dumping, exfiltrate data prior to encryption, and reboot systems into Safe Mode with Networking before encrypting files and appending .avos or .avos2 extensions. AvosLocker has been advertised on cybercrime forums including RAMP, where it was listed among RaaS programs and was noted posting buying requests on the same forum where it advertised its service. The content also places AvosLocker among ransomware groups targeting VMware ESXi environments and among more than 30 ransomware groups exploiting routinely exploited vulnerabilities. Additional reporting in the content states FIN7 sold its AvNeutralizer tool to multiple ransomware gangs including AvosLocker. The group is also mentioned in reporting on the post-Conti ecosystem: multiple sources cited in the content state Conti members dispersed into or partnered with operations including AvosLocker after Conti’s decline. The content does not attribute AvosLocker to a nation state.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
- 🇨🇦 Canada
- 🇬🇧 United Kingdom
- 🇦🇺 Australia
- 🇩🇪 Germany
- 🇫🇷 France
Tradecraft
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RaaS operation advertising on RAMP and directly seeking to buy or work corporate access such as VPN-to-RDP, Citrix, and webshell access.
Referenced as a ransomware group that some former Conti members allegedly joined after Conti’s retirement; described here as no longer active.
Named as a ransomware operation that former Conti members allegedly infiltrated or took over.
Referenced as a ransomware group reported to have obtained/used FIN7’s AvNeutralizer EDR-disabling tool.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.