AvosLocker
MITRE ATT&CK: S1053 View on attack.mitre.org
Aliases: Avos, AvosLocker
- First seen
- 2021-06-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- linux, windows
- Related IoCs
- 71 (71 malicious)
- Last IoC activity
- 2026-08-28 02:50:47
- Profile updated
- 2026-07-07 13:05:15
Targeted industries: financial-services government-and-public-sector manufacturing
Targeted regions: country_code:us country_code:be country_code:ca country_code:cn country_code:de country_code:sa country_code:es country_code:sy country_code:tw country_code:tr country_code:ae country_code:gb
Context
AvosLocker is ransomware written in C++ that has been offered via the Ransomware-as-a-Service (RaaS) model. It was first observed in June 2021 and has been used against financial services, critical manufacturing, government facilities, and other critical infrastructure sectors in the United States. As of March 2022, AvosLocker had also been used against organizations in Belgium, Canada, China, Germany, Saudi Arabia, Spain, Syria, Taiwan, Turkey, the United Arab Emirates, and the United Kingdom.
Recent IoC activity
71 malicious indicators in Maltiverse are attributed to AvosLocker (S1053). The 20 most recently updated:
Detection coverage
- 6 YARA rules
- 223 Sigma rules
Malware & tools used
- Native API (attack-pattern)
- Safe Mode Boot (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Dynamic API Resolution (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Masquerade File Type (attack-pattern)
- Hidden Window (attack-pattern)
- Service Stop (attack-pattern)
- Network Share Discovery (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- System Time Discovery (attack-pattern)
- Process Discovery (attack-pattern)
- System Shutdown/Reboot (attack-pattern)
Used by threat actors
- C0018 (campaign)
Detection rules
- MALPEDIA_Win_Avos_Locker_Auto (yara-rule)
- TRELLIX_ARC_Ransom_Avoslocker (yara-rule)
- ARKBIRD_SOLG_RAN_Avoslocker_July_2021_1 (yara-rule)
- DITEKSHEN_MALWARE_Win_Avoslocker (yara-rule)
- SEKOIA_Ransomware_Win_Avoslocker (yara-rule)
- SEKOIA_Ransomware_Lin_Avoslocker_Strings (yara-rule)
Related threat objects
- Avos (malware)
Reports & references
- advintel.io — Enter Karakurt Data Extortion Arm Of Prolific Ransomware Group (report)
- blogs.vmware.com — Esxi Targeting Ransomware The Threats That Are After Your Virtual Machines Part 1 (report)
- news.sophos.com — The Ransomware Threat Intelligence Center (report)
- Broadcom/Symantec — Sed Fy22Q2 Ses Ransomware Threat Landscape Wp (report)
- Palo Alto Unit 42 — Emerging Ransomware Groups (report)
- Broadcom/Symantec — Ransomware Hive Conti Avoslocker (report)
- advintel.io — Discontinued The End Of Conti S Brand Marks New Chapter For Cybercrime Landscape (report)
- avertium.com — In Depth Look At Avoslocker Ransomware (report)
- Palo Alto Unit 42 — Avoslocker Ransomware (report)
- kroll.com — Avoslocker Ransomware Update (report)
- picussecurity.com — Avos Locker Ransomware Group (report)
- brandefense.io — In Depth Analysis Of Avoslocker Ransomware (report)
- Cisco Talos — Avoslocker New Arsenal (report)
- techrepublic.com — Avos Ransomware Updates Attack (report)
- tripwire.com — Avoslocker Ransomware What You Need To Know (report)
- Trend Micro — Ransomware Spotlight Avoslocker (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Avoslocker (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Avos Locker (report)
- blogs.blackberry.com — Threat Thursday Avoslocker Prompts Advisory From Fbi And Fincen (report)
- ic3.gov — 220318 (report)
- blog.qualys.com — Avoslocker Ransomware Behavior Examined On Windows Linux (report)
- blog.lexfo.fr — Avoslocker (report)
- blogs.vmware.com — Avoslocker Modern Linux Ransomware Threats (report)
- blog.cyble.com — Avoslocker Ransomware Linux Version Targets Vmware Esxi Servers (report)
- malwarebytes.com — Avoslocker Enters The Ransomware Scene Asks For Partners (report)
External references
- mitre-attack — S1053
- Joint CSA AvosLocker Mar 2022
- Malwarebytes AvosLocker Jul 2021
- Trend Micro AvosLocker Apr 2022
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy