Malware.View on attack.mitre.org
Avaddon is ransomware written in C++ that has been offered as Ransomware-as-a-Service (RaaS) since at least June 2020.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
Avaddon can collect the external IP address of the victim. |
| T1027 Obfuscated Files or Information |
Avaddon has used encrypted strings. |
| T1047 Windows Management Instrumentation |
Avaddon uses wmic.exe to delete shadow copies. |
| T1057 Process Discovery |
Avaddon has collected information about running processes. |
| T1059.007 JavaScript |
Avaddon has been executed through a malicious JScript downloader. |
| T1083 File and Directory Discovery |
Avaddon has searched for specific files prior to encryption. |
| T1106 Native API |
Avaddon has used the Windows Crypto API to generate an AES key. |
| T1112 Modify Registry |
Avaddon modifies several registry keys for persistence and UAC bypass. |
| T1135 Network Share Discovery |
Avaddon has enumerated shared folders and mapped volumes. |
| T1140 Deobfuscate/Decode Files or Information |
Avaddon has decrypted encrypted strings. |
| T1486 Data Encrypted for Impact |
Avaddon encrypts the victim system using a combination of AES256 and RSA encryption schemes. |
| T1489 Service Stop |
Avaddon looks for and attempts to stop database processes. |
| T1490 Inhibit System Recovery |
Avaddon deletes backups and shadow copies using native system tools. |
| T1547.001 Registry Run Keys / Startup Folder |
Avaddon uses registry run keys for persistence. |
| T1548.002 Bypass User Account Control |
Avaddon bypasses UAC using the CMSTPLUA COM interface. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.