AvosLocker — Ransomware Profile
AvosLocker runs victims' systems in Safe Mode to bypass security tools, targeting critical infrastructure and financial services.Also tracked as
Avos RaaS, Avos
IntelFusions coverage (1)
- Akira reboots PCs into Safe Mode to blind security tools 2026-08-19 · Ransomware
Tools & malware
- AnyDesk Remote system administration tool abused for access
- aswArPot.sys Abused legitimate Avast Anti-Rootkit driver used to disable antivirus (BYOVD)
- Atera Agent Remote system administration tool abused for access
- AvosLocker Ransomware (encryptor; Windows, Linux, and VMware ESXi)
- Chisel Network tunneling tool
- Cobalt Strike Command-and-control framework
- FileZilla Data exfiltration tool
- Lazagne Credential-harvesting tool
- Ligolo Network tunneling tool
- Mimikatz Credential-harvesting tool
- NetMonitor.exe Custom persistence/reverse-proxy tool (FBI YARA-detected)
- Nltest Legitimate Windows tool abused for reconnaissance
- PDQ Deploy Software deployment tool abused for deployment
- PsExec Legitimate Windows tool abused for execution/lateral movement
- PuTTY Remote access tool
- Rclone Data exfiltration tool
- Sliver Command-and-control framework
- SoftPerfect Network Scanner Network scanning tool
- Splashtop Streamer Remote system administration tool abused for access
- Tactical RMM Remote system administration tool abused for access