ATT&CKReferencesCisco Talos Avos Jun 2022

Cisco Talos Avos Jun 2022

Venere, G. Neal, C. (2022, June 21). Avos ransomware group expands with new attack arsenal. Retrieved January 11, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns1

Procedure examples14

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
CampaignC0018

During C0018, the threat actors used Base64 to encode their PowerShell scripts.

T1036
Masquerading
CampaignC0018

During C0018, AvosLocker was disguised using the victim company name as the filename.

T1036.005
Match Legitimate Resource Name or Location
CampaignC0018

For C0018, the threat actors renamed a Sliver payload to `vmware_kb.exe`.

T1046
Network Service Discovery
CampaignC0018

During C0018, the threat actors used the SoftPerfect Network Scanner for network scanning.

T1047
Windows Management Instrumentation
CampaignC0018

During C0018, the threat actors used WMIC to modify administrative settings on both a local and a remote host, likely as part of the first stages for their lateral movement; they also used WMI Provider Host (`wmiprvse.exe`) to execute a variety of encoded PowerShell scripts using the `DownloadString` method.

T1059.001
PowerShell
CampaignC0018

During C0018, the threat actors used encoded PowerShell scripts for execution.

T1072
Software Deployment Tools
CampaignC0018

During C0018, the threat actors used PDQ Deploy to move AvosLocker and tools across the network.

T1105
Ingress Tool Transfer
CampaignC0018

During C0018, the threat actors downloaded additional tools, such as Mimikatz and Sliver, as well as Cobalt Strike and AvosLocker ransomware onto the victim network.

T1190
Exploit Public-Facing Application
CampaignC0018

During C0018, the threat actors exploited VMWare Horizon Unified Access Gateways that were vulnerable to several Log4Shell vulnerabilities, including CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832.

T1219.002
Remote Desktop Software
CampaignC0018

During C0018, the threat actors used AnyDesk to transfer tools between systems.

T1486
Data Encrypted for Impact
MalwareAvosLocker

AvosLocker has encrypted files and network resources using AES-256 and added an `.avos`, `.avos2`, or `.AvosLinux` extension to filenames.

T1486
Data Encrypted for Impact
CampaignC0018

During C0018, the threat actors used AvosLocker ransomware to encrypt files on the compromised network.

T1570
Lateral Tool Transfer
CampaignC0018

During C0018, the threat actors transferred the SoftPerfect Network Scanner and other tools to machines in the network using AnyDesk and PDQ Deploy.

T1588.002
Tool
CampaignC0018

For C0018, the threat actors acquired a variety of open source tools, including Mimikatz, Sliver, SoftPerfect Network Scanner, AnyDesk, and PDQ Deploy.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.