Malware.View on attack.mitre.org
AvosLocker is ransomware written in C++ that has been offered via the Ransomware-as-a-Service (RaaS) model. It was first observed in June 2021 and has been used against financial services, critical manufacturing, government facilities, and other critical infrastructure sectors in the United States. As of March 2022, AvosLocker had also been used against organizations in Belgium, Canada, China, Germany, Saudi Arabia, Spain, Syria, Taiwan, Turkey, the United Arab Emirates, and the United Kingdom.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
AvosLocker has used XOR-encoded strings. |
| T1027.007 Dynamic API Resolution |
AvosLocker has used obfuscated API calls that are retrieved by their checksums. |
| T1036.008 Masquerade File Type |
AvosLocker has been disguised as a .jpg file. |
| T1057 Process Discovery |
AvosLocker has discovered system processes by calling `RmGetList`. |
| T1083 File and Directory Discovery |
AvosLocker has searched for files and directories on a compromised network. |
| T1106 Native API |
AvosLocker has used a variety of Windows API calls, including `NtCurrentPeb` and `GetLogicalDrives`. |
| T1124 System Time Discovery |
AvosLocker has checked the system time before and after encryption. |
| T1135 Network Share Discovery |
AvosLocker has enumerated shared drives on a compromised network. |
| T1140 Deobfuscate/Decode Files or Information |
AvosLocker has deobfuscated XOR-encoded strings. |
| T1486 Data Encrypted for Impact |
AvosLocker has encrypted files and network resources using AES-256 and added an `.avos`, `.avos2`, or `.AvosLinux` extension to filenames. |
| T1489 Service Stop |
AvosLocker has terminated specific processes before encryption. |
| T1529 System Shutdown/Reboot |
AvosLocker’s Linux variant has terminated ESXi virtual machines. |
| T1547.001 Registry Run Keys / Startup Folder |
AvosLocker has been executed via the `RunOnce` Registry key to run itself on safe mode. |
| T1564.003 Hidden Window |
AvosLocker has hidden its console window by using the `ShowWindow` API function. |
| T1688 Safe Mode Boot |
AvosLocker can restart a compromised machine in safe mode. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.