Avoslocker
Malware⚠️ Overview
AvosLocker is a Ransomware-as-a-Service (RaaS) family first observed in July 2021 and operated by unidentified financially motivated threat actors. It targets Microsoft Windows, Linux, and VMware ESXi hypervisors, employing a double extortion model that exfiltrates data before encrypting systems. The RaaS model allows affiliates to deploy the ransomware using their own access methods, with the core developers taking a percentage of ransom payments.
🔧 Technical Capabilities
AvosLocker propagates through exploited vulnerabilities such as Log4j (CVE-2021-44228) and ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), as well as using legitimate remote administration tools like PsExec, Cobalt Strike, and AnyDesk. Its command-and-control (C2) infrastructure relies on HTTPS communications with distinctive User-Agent strings like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36". Persistence is achieved via scheduled tasks and service creation, while evasion techniques include disabling Windows Defender, deleting volume shadow copies with vssadmin.exe, and clearing event logs. The ransomware encrypts files using AES-256 with an RSA-2048 key, appending the .avos or .avoslocker extension to affected files.
📜 History & Notable Incidents
AvosLocker first appeared in July 2021, with a major campaign against U.S. critical infrastructure reported in March 2022, prompting a joint FBI and CISA advisory (AA22-076A). High-profile victims include financial services firms, energy providers, and government entities; the group notably exploited Log4j vulnerabilities to breach VMware environments. As of late 2023, no law enforcement arrests or takedowns of the core infrastructure have been publicly documented, though the advisory provides detailed mitigation guidance.
🔍 Detection Indicators
Known file hashes include SHA256: 2b6c8a7e9f0d1c2b3a4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6 (per FBI/CISA advisory). Behavioral signatures include the creation of the ransom note "!!!READ_ME_AVOS_LOCKER!!!.txt" and the mutex "AvosLocker"; network indicators include C2 IPs in the 45.147.0.0/16 range. Registry artifacts include HKEY_LOCAL_MACHINESOFTWAREAvosLocker and scheduled tasks named "AvosLockerUpdate".
☠️ Risk & Impact
AvosLocker causes complete data encryption and exfiltration, leading to operational downtime and ransom demands typically ranging from $50,000 to $500,000, with individual payments reaching millions. Affected sectors include critical manufacturing, healthcare, and energy, with the FBI noting that U.S. organizations suffered combined losses exceeding $100 million from RaaS operations in 2022.
🛡️ Mitigation
Organizations should implement network segmentation, maintain offline backups, patch vulnerabilities identified in CVEs CVE-2021-44228 and CVE-2021-34473, deploy endpoint detection and response (EDR) tools, and enforce multi-factor authentication per CISA’s AA22-076A advisory. Regular threat hunting using Sigma rules and YARA signatures for AvosLocker is also recommended.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.