HomeSecurityNew Avaddon Ransomware Appears in Massive Spam Campaign

New Avaddon Ransomware Appears in Massive Spam Campaign

The new Avaddon Ransomware comes to life in a massive spam campaign targeting users around the world.

Avaddon was released earlier this month and is recruiting active hackers and malware distributors to spread the ransomware in any way possible.

As its first known attack, the Avaddon Ransomware is being distributed in a spam campaign reminiscent of February's Nemty Ransomware Love Letter campaign.

Avaddon Ransomware

Do you like my photo?

In a wave of emails using subjects like "Do you like my photo?" or "Your new photo?", which contain nothing but the emoji 😉 in characters, a JavaScript downloader for the Avaddon ransomware is available.

Avaddon Ransomware

In a related report released, cybersecurity firm Appriver stated that the Phorphiex/Trik Botnet is distributing the malicious emails.

This campaign is no small one, as AppRiver security researcher David Picket told us that they had blocked over 300,000 emails in a short period of time.

Attached to these emails is a JavaScript file that is “disguised” as a JPG photo with names like IMG123101.jpg.

Now if you're wondering why someone would open a JavaScript file sent to them via email, it's important to remember that Windows hides the file extension by default, even though it's a known security risk.

This means that what the recipient sees will simply be a .jpg file, as shown below.

Avaddon Ransomware

When executed, the attached JS will launch a PowerShell and Bitsadmin command to download the Avaddon ransomware executable to the %Temp% folder and execute it.

New Avaddon Ransomware Appears in Massive Spam Campaign

In the sample tested by BleepingComputer, once executed, the ransomware will search for data to encrypt and add the .avdn extension to encrypted files.

Avaddon Ransomware

In each folder, a ransom note named [id]-readme.html will be created. This ransom note contains a link to the TOR website and a unique victim identifier used to log in to the website.

Avaddon Ransomware

This TOR payment website includes the ransom amount and instructions on how to pay for a decryptor.

New Avaddon Ransomware Appears in Massive Spam Campaign

Other sections of the TOR website include a support chat, a free decryption trial, and a help page decorated with Harry Potter.

New Avaddon Ransomware Appears in Massive Spam Campaign

Unfortunately, Michael Gillespie analyzed the ransomware and stated that it is safe and cannot be decrypted for free.

New Avaddon Ransomware Appears in Massive Spam Campaign

In advertisements posted on Russian-language hacking forums earlier this month, Avaddon claimed to be a new Ransomware-as-an-Affiliate (RaaS) program.

This means that the ransomware creator is responsible for developing the malware and operating the TOR.

Partners participating in the program are responsible for distributing ransomware through spam, compromised networks, and exploit kits.

Under this agreement, Avaddon pays partners 65% of the ransom they bring in, and Avaddon providers will receive 35%. Larger partners are usually able to negotiate a higher revenue share depending on the size of their attacks.

As is typical with RaaS programs, Avaddon has a set of rules that partners must follow when distributing ransomware. The most common rule is that they cannot target victims in the Commonwealth of Independent States (CIS).

Now that Avaddon's creators have started accepting applications, we should expect to see an increase in distribution and more advanced attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS