Description
[Avaddon](https://attack.mitre.org/software/S0640) is ransomware written in C++ that has been offered as Ransomware-as-a-Service (RaaS) since at least June 2020.(Citation: Awake Security Avaddon)(Citation: Arxiv Avaddon Feb 2021)
External References
Techniques Used by This Malware
- T1016 — System Network Configuration Discovery
- T1027 — Obfuscated Files or Information
- T1047 — Windows Management Instrumentation
- T1057 — Process Discovery
- T1059.007 — JavaScript
- T1083 — File and Directory Discovery
- T1106 — Native API
- T1112 — Modify Registry
- T1135 — Network Share Discovery
- T1140 — Deobfuscate/Decode Files or Information
- T1486 — Data Encrypted for Impact
- T1489 — Service Stop
- T1490 — Inhibit System Recovery
- T1547.001 — Registry Run Keys / Startup Folder
- T1548.002 — Bypass User Account Control
- T1562.001 — Disable or Modify Tools
- T1614.001 — System Language Discovery