The new Avaddon Ransomware comes to life in a massive spam campaign targeting users around the world.
Avaddon was released earlier this month and is recruiting active hackers and malware distributors to spread the ransomware in any way possible.
As its first known attack, the Avaddon Ransomware is being distributed in a spam campaign reminiscent of February's Nemty Ransomware Love Letter campaign.

Do you like my photo?
In a wave of emails using subjects like "Do you like my photo?" or "Your new photo?", which contain nothing but the emoji 😉 in characters, a JavaScript downloader for the Avaddon ransomware is available.

In a related report released, cybersecurity firm Appriver stated that the Phorphiex/Trik Botnet is distributing the malicious emails.
This campaign is no small one, as AppRiver security researcher David Picket told us that they had blocked over 300,000 emails in a short period of time.
Attached to these emails is a JavaScript file that is “disguised” as a JPG photo with names like IMG123101.jpg.
Now if you're wondering why someone would open a JavaScript file sent to them via email, it's important to remember that Windows hides the file extension by default, even though it's a known security risk.
This means that what the recipient sees will simply be a .jpg file, as shown below.

When executed, the attached JS will launch a PowerShell and Bitsadmin command to download the Avaddon ransomware executable to the %Temp% folder and execute it.

In the sample tested by BleepingComputer, once executed, the ransomware will search for data to encrypt and add the .avdn extension to encrypted files.

In each folder, a ransom note named [id]-readme.html will be created. This ransom note contains a link to the TOR website and a unique victim identifier used to log in to the website.

This TOR payment website includes the ransom amount and instructions on how to pay for a decryptor.

Other sections of the TOR website include a support chat, a free decryption trial, and a help page decorated with Harry Potter.

Unfortunately, Michael Gillespie analyzed the ransomware and stated that it is safe and cannot be decrypted for free.

In advertisements posted on Russian-language hacking forums earlier this month, Avaddon claimed to be a new Ransomware-as-an-Affiliate (RaaS) program.
This means that the ransomware creator is responsible for developing the malware and operating the TOR.
Partners participating in the program are responsible for distributing ransomware through spam, compromised networks, and exploit kits.
Under this agreement, Avaddon pays partners 65% of the ransom they bring in, and Avaddon providers will receive 35%. Larger partners are usually able to negotiate a higher revenue share depending on the size of their attacks.
As is typical with RaaS programs, Avaddon has a set of rules that partners must follow when distributing ransomware. The most common rule is that they cannot target victims in the Commonwealth of Independent States (CIS).
Now that Avaddon's creators have started accepting applications, we should expect to see an increase in distribution and more advanced attacks.
