Riddle Spider Avaddon Ransomware Analysis and Technical Overview

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

Riddle Spider Avaddon Ransomware Analysis and Technical Overview

Emerging in June 2020, the Avaddon ransomware operation rapidly established itself as a significant threat within the cybercrime ecosystem through a highly organized Ransomware-as-a-Service (RaaS) model. The campaign was characterized by its use of double extortion tactics, where victims faced not only the encryption of critical data but also the threat of having sensitive information published on a dedicated leak site if ransom demands were not met. The development and overall management of this RaaS enterprise are attributed to the threat actor tracked as Riddle Spider [1]. The operation follows a typical affiliate model where profits are split between the operators and affiliates, often starting at a 35/65 split.

In this blog, we will analyze the technical characteristics of the Avaddon ransomware associated with the Riddle Spider group.

Article Link: Riddle Spider Avaddon Ransomware Analysis and Technical Overview

1 post - 1 participant

Read full topic



Malware Analysis, News and Indicators - Latest topics
Next Post Previous Post