Avos ransomware group
Avos is one of the extortion operations we watch continuously. This page covers what is known about the group and the current state of its leak site, which we last saw change 5y ago.
Who they are
First observed in July 2021, AvosLocker operates as a Ransomware-as-a-Service (RaaS) platform employing a double-extortion model—encrypting files and exfiltrating data with threats to leak it publicly. Its affiliates have targeted diverse environments including Windows, Linux, and VMware ESXi, particularly impacting sectors such as education, government, manufacturing, and healthcare across the U.S., Canada, and numerous other countries. Affiliates gain access through phishing emails, exploitation of vulnerabilities (notably Microsoft Exchange ProxyShell/log4j, Zoho ManageEngine), and compromised remote services. Technically, AvosLocker uses AES (with RSA-wrapped keys) for file encryption, often executing in safe mode to bypass security defenses, and directs victims to ransom notes like GET_YOUR_FILES_BACK.txt while changing the desktop wallpaper. Its data leak site operated from mid-2021 until about July–August 2023. No activity has been observed since May 2023.
Current status
Avos's leak site is not answering. Sites go dark for infrastructure trouble, a deliberate quiet period, or a takedown, and a good number return weeks later under the same name, so the entry stays on the list either way.
The last change we recorded on it was 5y ago (1 May 2021 00:00 UTC).
Which organisations this group has named, and when, is part of the SINON platform rather than this page. Create an account to search it, or to be told automatically if a name you care about turns up.
Sectors targeted
This group does not state an industry on its site, so we have nothing reliable to report. Most crews are opportunistic rather than sector-specific in any case — they hit what they can reach.
Watching for your name
If Avos posts your company, a supplier or a subsidiary, you want to hear it from us rather than from a journalist. SINON checks these sites continuously and alerts on the names you give it.
Start monitoring