Avaddon

Inactive
Avaddon is a ransomware malware targeting Windows systems often spread via malicious spam. The first known attack where Avaddon ransomware was distributed was in February 2020. Avaddon encrypts files using the extension .avdn and uses a TOR payment site for the ransom payment.
146 Victims
Jan 31, 2021 First Discovered
Sep 9, 2021 Last Discovered
1833 Days Inactive
0% Infostealer
0/1 Sites Online
Known Locations (1)
avaddongun7rngel.onion
Tools Used
CredentialTheft
Mimikatz, SharpDump
DefenseEvasion
GMER, PowerTool, TDSSKiller
DiscoveryEnum
SoftPerfect NetScan
Exfiltration
Anonfiles, MEGA, ProtonMail, Sendspace
Offsec
PowerShell Empire, PowerSploit
Intelligence
Victims (146)

Detailed victim list temporarily unavailable

This group has 146 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.