AvosLocker is the ransomware payload of the Avos RaaS group, active from July 2021 to approximately May 2023, targeting education, manufacturing, and healthcare sectors on Windows, Linux, and VMware ESXi environments, with the US accounting for ~72% of victims.
Cross-platform with Linux/Windows variants
Deletes shadow copies
Disables antivirus via Safe Mode boot
Uses AnyDesk for remote access