(Cornell University) The commoditization of Malware-as-a-Service (MaaS) allows criminals to obtain financial benefits at a low risk and with little technical background. One such popular product in the underground economy is ransomware. In ransomware attacks, data from infected systems is held hostage (encrypted) until a fee is paid to the criminals. This modus operandi disrupts legitimate businesses, which may become unavailable until the data is restored. A recent blackmailing strategy adopted by criminals is to leak data online from the infected systems if the ransom is not paid. Besides reputational damage, data leakage might produce further economical losses due to fines imposed by data protection laws. Thus, research on prevention and recovery measures to mitigate the impact of such attacks is needed to adapt existing countermeasures to new strains.
TA0043 | TA0042 | TA0001 | TA0002 | TA0003 | TA0004 | TA0005 | TA0006 | TA0007 | TA0008 | TA0009 | TA0011 | TA0010 | TA0040 |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
IP:Port | Timestamp |
---|
Domain | Timestamp |
---|
URL | Timestamp |
---|
Actor: Riddle Spider
Names: Riddle Spider, Avaddon Team
Country: [Unknown]
Motivation: Financial gain
First-seen: 2020
Description: (Cornell University) The commoditization of Malware-as-a-Service (MaaS) allows criminals to obtain financial benefits at a low risk and with little technical background. One such popular product in the underground economy is ransomware. In ransomware attacks, data from infected systems is held hostage (encrypted) until a fee is paid to the criminals. This modus operandi disrupts legitimate businesses, which may become unavailable until the data is restored. A recent blackmailing strategy adopted by criminals is to leak data online from the infected systems if the ransom is not paid. Besides reputational damage, data leakage might produce further economical losses due to fines imposed by data protection laws. Thus, research on prevention and recovery measures to mitigate the impact of such attacks is needed to adapt existing countermeasures to new strains.
Observed-countries: Australia
Observed-countries: Belgium
Observed-countries: Brazil
Observed-countries: Canada
Observed-countries: China
Observed-countries: Costa Rica
Observed-countries: Czech
Observed-countries: France
Observed-countries: Germany
Observed-countries: India
Observed-countries: Indonesia
Observed-countries: Italy
Observed-countries: Japan
Observed-countries: Jordan
Observed-countries: Peru
Observed-countries: Poland
Observed-countries: Portugal
Observed-countries: Russia
Observed-countries: South Korea
Observed-countries: Spain
Observed-countries: Switzerland
Observed-countries: Thailand
Observed-countries: UAE
Observed-countries: UK
Observed-countries: USA
Observed-countries: Worldwide
Tools: Avaddon
Operations: 2020-06
Operations: New Avaddon Ransomware launches in massive smiley spam campaign https://www.bleepingcomputer.com/news/security/new-avaddon-ransomware-launches-in-massive-smiley-spam-campaign/
Operations: 2020-07
Operations: Avaddon ransomware shows that Excel 4.0 macros are still effective https://www.bleepingcomputer.com/news/security/avaddon-ransomware-shows-that-excel-40-macros-are-still-effective/
Operations: 2020-08
Operations: Avaddon ransomware launches data leak site to extort victims https://www.bleepingcomputer.com/news/security/avaddon-ransomware-launches-data-leak-site-to-extort-victims/
Operations: 2021-01
Operations: Another ransomware now uses DDoS attacks to force victims to pay https://www.bleepingcomputer.com/news/security/another-ransomware-now-uses-ddos-attacks-to-force-victims-to-pay/
Operations: 2021-02
Operations: Avaddon ransomware fixes flaw allowing free decryption https://www.bleepingcomputer.com/news/security/avaddon-ransomware-fixes-flaw-allowing-free-decryption/
Operations: 2021-04
Operations: Cyber-attackers hold PN to ransom with major data leak threat https://timesofmalta.com/articles/view/cyber-attackers-hold-pn-to-ransom-with-major-data-leak-threat.865968
Operations: 2021-05
Operations: Insurer AXA hit by ransomware after dropping support for ransom payments https://www.bleepingcomputer.com/news/security/insurer-axa-hit-by-ransomware-after-dropping-support-for-ransom-payments/
Operations: 2021-06
Operations: Avaddon ransomware shuts down and releases decryption keys https://www.bleepingcomputer.com/news/security/avaddon-ransomware-shuts-down-and-releases-decryption-keys/
Information: https://arxiv.org/abs/2102.04796
Last-card-change: 2021-06-15
Source: https://apt.etda.or.th/cgi-bin/listtools.cgi
TA0043 | TA0042 | TA0001 | TA0002 | TA0003 | TA0004 | TA0005 | TA0006 | TA0007 | TA0008 | TA0009 | TA0011 | TA0010 | TA0040 |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
T1059.007 COMMAND AND SCRIPTING INTERPRETER : JAVASCRIPT avaddon has been executed through a malicious jscript downloader. | T1547.001 BOOT OR LOGON AUTOSTART EXECUTION : REGISTRY RUN KEYS / STARTUP FOLDER avaddon uses registry run keys for persistence. | T1548.002 ABUSE ELEVATION CONTROL MECHANISM : BYPASS USER ACCOUNT CONTROL avaddon bypasses uac using the cmstplua com interface. T1547.001 BOOT OR LOGON AUTOSTART EXECUTION : REGISTRY RUN KEYS / STARTUP FOLDER avaddon uses registry run keys for persistence. | T1548.002 ABUSE ELEVATION CONTROL MECHANISM : BYPASS USER ACCOUNT CONTROL avaddon bypasses uac using the cmstplua com interface. T1562.001 IMPAIR DEFENSES : DISABLE OR MODIFY TOOLS avaddon looks for and attempts to stop anti-malware solutions. | T1614.001 SYSTEM LOCATION DISCOVERY : SYSTEM LANGUAGE DISCOVERY avaddon checks for specific keyboard layouts and os languages to avoid targeting commonwealth of independent states (cis) entities. T1016 SYSTEM NETWORK CONFIGURATION DISCOVERY avaddon can collect the external ip address of the victim. | T1486 DATA ENCRYPTED FOR IMPACT avaddon encrypts the victim system using a combination of aes256 and rsa encryption schemes. |