October 07, 2020 — 9 min read
Avaddon ransomware cleans the bin for you
Avaddon is a new Maze-like ransomware that not only encrypts the user’s data but also steals it and threatens to make it public. To do that, the Avaddon operator recently launched their own data leak site, where they have already published data from Liberty Linehaul and U.S. Auto Parts Network, Inc. What makes this ransomware unique is the way it tries to delete backups. In addition to traditional removal of shadow copies of the user’s files, Avaddon also deletes system backups, disables automatic repair and recovery, and cleans the bin. To do that, it escalates privileges with UAC bypassing through CMSTPLUA COM interface exploitation.