TL;DR
This paper provides a comprehensive analysis of the Avaddon ransomware, detailing its criminal business model, technical features, and offering a real-time decryption tool to mitigate its impact, including empirical evidence linking it to previous malware families.
Contribution
It introduces a detailed analysis of Avaddon ransomware's operations and technical capabilities, and presents an open-source real-time decryptor for infected systems.
Findings
Identified links between Avaddon and previous ransomware families.
Developed a real-time decryption tool for Avaddon-encrypted files.
Documented the criminal business model and attack strategies of Avaddon.
Abstract
The commoditization of Malware-as-a-Service (MaaS) allows criminals to obtain financial benefits at a low risk and with little technical background. One such popular product in the underground economy is ransomware. In ransomware attacks, data from infected systems is held hostage (encrypted) until a fee is paid to the criminals. This modus operandi disrupts legitimate businesses, which may become unavailable until the data is restored. A recent blackmailing strategy adopted by criminals is to leak data online from the infected systems if the ransom is not paid. Besides reputational damage, data leakage might produce further economical losses due to fines imposed by data protection laws. Thus, research on prevention and recovery measures to mitigate the impact of such attacks is needed to adapt existing countermeasures to new strains. In this work, we perform an in-depth analysis of…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
