logo

AvosLocker

ID: a9b99ffd-59e0-58e4-bf8c-b632b878ffda

STIX ID: report--a9b99ffd-59e0-58e4-bf8c-b632b878ffda

Feed Name: Zscaler Security Research Blog

Threat Score
80/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report provides a detailed technical analysis of the AvosLocker ransomware (observed since 2021), describing its configurable command-line options, pre-encryption cleanup (process termination, shadow copy and event log deletion, boot policy changes), multi-threaded AES-CBC encryption with RSA-2048-wrapped keys appended to files, file/ folder exclusion lists, observable IOCs (mutex, extensions .avos/.avos2/.avoslinux, ransom note names), and both Windows and Linux/ESXi behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.