Avos
From extortion.wiki, the ransomware negotiation research archive
Negotiation records classified under Avos in the current Ransomchats snapshot. This page indexes the source label; it does not independently verify attribution.
Classification follows the source dataset. Metadata is useful. It is not testimony.
Actor lineage
Global lineage directoryOverview
AvosLocker is documented as a RaaS variant with affiliates. The archive preserves the original Ransomchats label “Avos” separately from this normalized display name.
Documentary media

Known aliases
| Alias | Type | First observed | Last observed | Confidence | Sources |
|---|---|---|---|---|---|
| AvosAvos is the source label in Ransomchats. The canonical AvosLocker display is an explicit archive normalization backed by the corresponding government advisory; it does not confirm the identity of every user of the malware. | Operation name | Date not established | Date not established | Moderate confidence | Casualtek · FBI and CISA |
Historical timeline
-
AvosLocker first observed
AvosLocker first observed
MITRE records AvosLocker as first observed in June 2021.
Evidence status: officially confirmed High confidence
Lineage and relationships
No evidence-backed relationship is currently recorded. Similar code, language, infrastructure style, or negotiation behavior is not enough on its own.
Predecessors
None established.
Successors
None established.
Splits and mergers
None established.
Suspected affiliate relationships
None established.
MITRE ATT&CK integration
No explicit MITRE ATT&CK group mapping is published for this source label. Software entries and fuzzy name matches are not promoted to group mappings.
External intelligence references
- Casualtek/RansomchatsCasualtek · dataset provenance · context only
- #StopRansomware: AvosLocker Ransomware (Update)FBI and CISA · government advisory · primary authoritative
- AvosLocker, Software S1053MITRE ATT&CK · MITRE ATTACK · authoritative secondary
Confidence and evidence notes
Confidence applies to each individual alias, event, or relationship—not to the actor page as a whole. “Confirmed” requires explicit authoritative attribution or multiple strong independent sources. Moderate, low, disputed, and unknown entries retain the source's uncertainty. A malware-family name is not automatically an actor identity, and shared code or affiliates do not prove shared leadership.
Ransomware notes
Browse Avoslocker notesThe explicit archive alias mapping connects this Ransomchats actor label to the ThreatLabz family Avoslocker. Its 1 archived note is counted and searched separately from the negotiation records below.
Search within this collection
Negotiation records
No matching records
No records match the current filters. Remove one before blaming the archive.