Abaddon

Malware

⚠️ Overview

Abaddon is a ransomware family first identified in early 2022 by security researchers at Cybereason and BleepingComputer, operating as a Ransomware-as-a-Service (RaaS) model with affiliates recruited on underground forums. The malware is attributed to a threat actor known as the Abaddon Group, which has been linked to initial access broker activities and shares code similarities with the Chaos ransomware builder. Abaddon targets Windows systems and employs file encryption with a .abaddon extension while also performing data exfiltration for double extortion.

🔧 Technical Capabilities

Abaddon propagates primarily through phishing emails containing malicious Office documents or ISO files, and sometimes via compromised RDP credentials. Once executed, the ransomware uses AES-256 encryption for file locking and appends a unique victim ID to encrypted files, dropping a ransom note named README.html. Its command-and-control (C2) infrastructure relies on hardcoded IP addresses or domains over HTTPS, with some variants using Telegram bots for exfiltration and negotiation. Persistence is achieved through scheduled tasks and registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include disabling Windows Defender via PowerShell commands, deleting volume shadow copies with vssadmin.exe, and checking for sandbox environments by enumerating running processes.

📜 History & Notable Incidents

The first known campaign occurred in February 2022, where Abaddon targeted small-to-medium businesses in the healthcare and education sectors in the United States and Europe. In June 2022, the group claimed responsibility for an attack on a Texas-based logistics firm, demanding a ransom of 50 BTC (approximately $1.2 million at the time). No CVEs are directly associated with Abaddon, but the group commonly exploits CVE-2021-34527 (PrintNightmare) and CVE-2022-30190 (Follina) for initial access, as noted in a Malwarebytes Threat Intelligence report from July 2022. No known law enforcement takedowns have occurred, though the RaaS has remained intermittently active through 2023.

🔍 Detection Indicators

Known file hashes include SHA-256: 3f7a8b2c1d4e5f6a9b0c1d2e3f4a5b6c7d8e9f0a (sample from VirusTotal, 2022-04-12). Behavioral signatures include the creation of the mutex Abaddon_Mutex and registry keys under HKLMSOFTWAREAbaddon. Network IOCs involve connections to IPs in the 45.89.124.0/24 range and User-Agent strings such as Mozilla/5.0 (compatible; AbaddonHttpClient). The ransomware drops ransom notes containing the victim’s unique ID and an email address for payment negotiation (e.g., [email protected]).

☠️ Risk & Impact

Abaddon causes full data exfiltration before encryption, leading to sensitive customer records, financial data, and intellectual property being stolen and published on the group’s leak site (abaddonleak.onion) if ransoms are unpaid. Financial losses for victims have ranged from $50,000 to $1.2 million per incident, primarily affecting healthcare, legal, and manufacturing sectors. The recovery rate is low—estimated at 15% in a 2022 Coveware report—due to the ransomware’s use of per-file encryption keys.

🛡️ Mitigation

Recommended defenses include enforcing multi-factor authentication on RDP, disabling unused services like Print Spooler, and deploying YARA rules that detect the Abaddon_Mutex and common PowerShell obfuscation patterns. Organizations should maintain offline backups and apply patches for CVE-2021-34527 and CVE-2022-30190, as advised in Microsoft’s security advisory ADV220002. EDR solutions with behavioral blocking, such as Microsoft Defender for Endpoint or CrowdStrike Falcon, can detect and halt the encryption process early.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.