Netskope Threat Labs

AvosLocker

ATP Sandbox Adv. HeuristicsAVNetskope IPS

AvosLocker is a C++ ransomware offered through the ransomware as a service model since June 2021. Its affiliates have used it against financial services, critical manufacturing, government facilities, and other critical infrastructure sectors in the United States, with victims also reported in Belgium, Canada, China, Germany, Saudi Arabia, Spain, Syria, Taiwan, Turkey, the United Arab Emirates, and the United Kingdom.

First seen
February 2022
Last seen
October 2026
AVOSLockerAvoslocker

15 techniques across 6 tactics.

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0007 Discovery

  • T1057Process Discovery
  • T1083File and Directory Discovery
  • T1124System Time Discovery
  • T1135Network Share Discovery

TA0040 Impact

TA0112 Defense Impairment

Alert Name
DeepScan:Generic.Ransom.AVOSLocker.A.508E1AC6
DeepScan:Generic.Ransom.AVOSLocker.A.CD728D09
DeepScan:Generic.Ransom.AVOSLocker.A.FC3F0A6C
Dump:Generic.Ransom.AVOSLocker.A.508E1AC6
Dump:Generic.Ransom.AVOSLocker.A.CD728D09
Gen:Variant.Ransom.AVOSLocker.11
Gen:Variant.Ransom.AvosLocker.22
Gen:Variant.Ransom.Ransomare.AvosLocker.3
Gen:Variant.Ransomware.Linux.AvosLocker.1
Linux.Ransomware.Avoslocker