Inactive ransomware operator
← All groupsAvoslocker
aka Avos · 70 victims indexed · first seen 5 years ago · last activity 3 years ago
At a glance
- Status
- inactive
- Aliases
- Avos
- First seen
- 5 years ago
- Last activity
- 3 years ago
- Onion sites
- 3 known endpoints
- Primary sector
- Education · 4 hits
About
References
38 linksExternal sources curated by the MISP threat-intel community.
- avertium.com/resources/threat-reports/in-depth-look-at-avoslocker-ransomware
- unit42.paloaltonetworks.com/atoms/avoslocker-ransomware/
- kroll.com/en/insights/publications/cyber/avoslocker-ransomware-update
- picussecurity.com/resource/avos-locker-ransomware-group
- brandefense.io/blog/ransomware/in-depth-analysis-of-avoslocker-ransomware/
- blog.talosintelligence.com/avoslocker-new-arsenal/
- techrepublic.com/article/avos-ransomware-updates-attack/
- tripwire.com/state-of-security/avoslocker-ransomware-what-you-need-to-know
- trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-avoslocker
- malpedia.caad.fkie.fraunhofer.de/details/elf.avoslocker
- malpedia.caad.fkie.fraunhofer.de/details/win.avos_locker
- blogs.vmware.com/security/2022/09/esxi-targeting-ransomware-the-threats-that-are-after-your-virtual-machines-part-1.html
- blogs.blackberry.com/en/2022/04/threat-thursday-avoslocker-prompts-advisory-from-fbi-and-fincen
- ic3.gov/Media/News/2022/220318.pdf
- blog.qualys.com/vulnerabilities-threat-research/2022/03/06/avoslocker-ransomware-behavior-examined-on-windows-linux
- blog.lexfo.fr/Avoslocker.html
- blogs.vmware.com/security/2022/02/avoslocker-modern-linux-ransomware-threats.html
- blog.cyble.com/2022/01/17/avoslocker-ransomware-linux-version-targets-vmware-esxi-servers/
- malwarebytes.com/blog/threat-intelligence/2021/07/avoslocker-enters-the-ransomware-scene-asks-for-partners
- unit42.paloaltonetworks.com/emerging-ransomware-groups/
Timeline
6 monthsTop countries
Top sectors
MITRE ATT&CK
5 techniques · 4 tacticsTactics
Detection · YARA rules
1 ruleRansom_AvosLocker
YARA rule from ATR/Trellix: ransomware/RANSOM_Avoslocker.yar
source: ATR/Trellix
Recent victims
Loading…
Onion infrastructure
3 known- http://avosjon4pfh3y7ew3jdwz6ofw7lljcxlbk7hcxxmnxlh5kvf2akcqjad.onion
- http://avosqxh72b5ia23dl5fgwcpndkctuzqvh2iefk5imp3pi5gfhel5klad.onion
- http://avosqxh72b5ia23dl5fgwcpndkctuzqvh2iefk5imp3pi5gfhel5klad.onion/
Source
Updated 3 years agoData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
