The Federal Bureau of Investigation (FBI) published a joint cybersecurity advisory warning of AvosLocker ransomware attacks targeting multiple US critical infrastructure.
The advisory was published in coordination with the US Treasury Department and the Financial Crimes Enforcement Network (FinCEN).
“AvosLocker is a Ransomware as a Service (RaaS) affiliate-based group that has targeted victims across multiple critical infrastructure sectors in the United States including, but not limited to, the Financial Services, Critical Manufacturing, and Government Facilities sectors. AvosLocker claims to directly handle ransom negotiations, as well as the publishing and hosting of exfiltrated victim data after their affiliates infect targets.” reads the report published by the company. “As a result, AvosLocker indicators of compromise (IOCs) vary between indicators specific to AvosLocker malware and indicators specific to the individual affiliate responsible for the intrusion.”
The joint advisory includes indicators of compromise (IOCs) that network defenders can use to detect and block the threat.
The AvosLocker ransomware-as-a-service emerged in the threat landscape in September 2021, since January the group expanded its targets by implementing the support for encrypting Linux systems, specifically VMware ESXi servers.
AvosLocker operators already advertised in the past a Linux variant, dubbed AvosLinux, of their malware claiming it was able to support Linux and ESXi servers.
The AvosLocker ransomware appends the .avoslinux extension to the filenames of all the encrypted files, then drops ransom notes in each folder containing the encrypted files.
The alert revealed that in some cases, the AvosLocker ransomware operators targeted victims with phone calls encouraging them to go to the onion site to negotiate and threatens to leak the stolen data online. In some cases, the gang also threatened and conducted distributed denial-of-service (DDoS) attacks during negotiations.
The AvosLocker leak site claims to have hit victims in the United States, Syria, Saudi
Arabia, Germany, Spain, Belgium, Turkey, the United Arab Emirates, the United Kingdom,
Canada, China, and Taiwan.
In some cases, AvosLocker negotiators also threaten and launche distributed denial-of-service (DDoS) attacks during negotiations, likely when the victims are not cooperating, to convince them to comply with their demands.
The report also includes a list of mitigation measures to increase the resilience of company networks:
Follow me on Twitter: @securityaffairs and Facebook
[adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, AvosLocker ransomware)
[adrotate banner=”5″]
[adrotate banner=”13″]