logo

A Deep-dive Analysis of the AvosLocker Ransomware

ID: ec8b38d0-e0e5-5c0c-bb72-e31bb41260f7

STIX ID: report--ec8b38d0-e0e5-5c0c-bb72-e31bb41260f7

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-11-17

Date Updated: 2026-07-16

...
...

This report from Cyble Research Lab analyzes the AvosLocker ransomware: a Windows console-based C/C++ ransomware that encrypts files (appending .avos), targets network shares, uses AES-256, employs techniques such as Restart Manager and process termination, creates GET_YOUR_FILES_BACK.txt ransom notes pointing to an onion site, and includes IOCs (a SHA-256 hash and a mutex name) plus recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.