RIDDLE SPIDER
Also reported as Riddle Spider and Avaddon Team.
Reports per quarter
CVEs named in reports
- CVE-2012-0158 KEV ransomware
- CVE-2012-5687
- CVE-2013-5947
- CVE-2013-7389
- CVE-2014-1225
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-2051 KEV
- CVE-2015-7248
Show all 126 CVEs Show fewer
- CVE-2015-7254
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2018-10562 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11634 KEV ransomware
- CVE-2019-15126
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-5591 KEV ransomware
- CVE-2019-7481 KEV ransomware
- CVE-2019-9670 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0787 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-12271 KEV ransomware
- CVE-2020-12812 KEV ransomware
- CVE-2020-1472 KEV ransomware
- CVE-2020-14882 KEV
- CVE-2020-15892
- CVE-2020-15893
- CVE-2020-15894
- CVE-2020-15895
- CVE-2020-15896
- CVE-2020-2021 KEV ransomware
- CVE-2020-36198
- CVE-2020-3702
- CVE-2020-5135 KEV ransomware
- CVE-2020-8195 KEV
- CVE-2020-8196 KEV
- CVE-2020-8234
- CVE-2020-8260 KEV
- CVE-2021-1732 KEV ransomware
- CVE-2021-1879 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-20028 KEV ransomware
- CVE-2021-20655
- CVE-2021-21166 KEV
- CVE-2021-2198
- CVE-2021-21985 KEV ransomware
- CVE-2021-22893 KEV ransomware
- CVE-2021-22941 KEV ransomware
- CVE-2021-22986 KEV ransomware
- CVE-2021-25323
- CVE-2021-25324
- CVE-2021-25325
- CVE-2021-26084 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-26868
- CVE-2021-2701
- CVE-2021-27065 KEV ransomware
- CVE-2021-27101 KEV ransomware
- CVE-2021-27102 KEV ransomware
- CVE-2021-27103 KEV ransomware
- CVE-2021-27104 KEV ransomware
- CVE-2021-28310 KEV
- CVE-2021-28799 KEV ransomware
- CVE-2021-30116 KEV ransomware
- CVE-2021-30551 KEV
- CVE-2021-30657 KEV
- CVE-2021-31166 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-33742 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-36942 KEV ransomware
- CVE-2021-38647 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2021-45046 KEV ransomware
- CVE-2022-1388 KEV ransomware
- CVE-2022-22954 KEV ransomware
- CVE-2022-22960 KEV
- CVE-2022-26134 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2023-0669 KEV ransomware
- CVE-2023-20269 KEV ransomware
- CVE-2023-22515 KEV ransomware
- CVE-2023-22518 KEV ransomware
- CVE-2023-27350 KEV ransomware
- CVE-2023-27351 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-34048 KEV
- CVE-2023-34362 KEV ransomware
- CVE-2023-3466
- CVE-2023-3467
- CVE-2023-3519 KEV ransomware
- CVE-2023-36884 KEV ransomware
- CVE-2023-38831 KEV ransomware
- CVE-2023-40044 KEV ransomware
- CVE-2023-42793 KEV ransomware
- CVE-2023-46604 KEV ransomware
- CVE-2023-47246 KEV ransomware
- CVE-2023-4911 KEV
- CVE-2023-4966 KEV ransomware
- CVE-2023-50164
- CVE-2024-30051 KEV ransomware
- CVE-2025-0411 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor TEARDROP (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Amadey (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor RagnarLocker (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Hades (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor SUNBURST (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor SystemBC (Malware Family)
Show all 125 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor QakBot (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Nefilim (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor DanaBot (Malware Family)
-
BazarBackdoor (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BazarBackdoor (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Clop (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Conti (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor REvil (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor SmokeLoader (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Babuk (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Dridex (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PyXie (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor IcedID (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor WastedLocker (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Zloader (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor DarkSide (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor MedusaLocker (Malware Family)
-
Cobalt Strike (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cobalt Strike (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ryuk (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Maze (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BlackMatter (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BlackMatter (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Egregor (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor LockBit (Malware Family)
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor watchtower-2023-eoy-report-en
-
“BazarCall” Advisory- Essential Guide to Attack Vector that Revolutionized Data Breaches
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor “BazarCall” Advisory- Essential Guide to Attack Vector that Revolutionized Data Breaches
-
LockBit 2.0- How This RaaS Operates and How to Protect Against It
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor LockBit 2.0- How This RaaS Operates and How to Protect Against It
-
yir-cyber-threats-report-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-report-download.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Profile- Avaddon
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware Threat Report 2022
-
The Ransomware Threat Intelligence Center
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Ransomware Threat Intelligence Center
-
An Empirically Comparative Analysis of Ransomware Binaries
The original link failed its last check. Original publisher Detailsfor An Empirically Comparative Analysis of Ransomware Binaries
-
ALPHV ransomware gang analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ALPHV ransomware gang analysis
-
One Source to Rule Them All- Chasing AVADDON Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor One Source to Rule Them All- Chasing AVADDON Ransomware
-
Storm in -Safe Haven-- Takeaways from Russian Authorities Takedown of REvil
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Storm in -Safe Haven-- Takeaways from Russian Authorities Takedown of REvil
-
ECX- Big Game Hunting on the Rise Following a Notable Reduction in Activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ECX- Big Game Hunting on the Rise Following a Notable Reduction in Activity
-
Big Game Hunting TTPs Continue to Shift After DarkSide Pipeline Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Big Game Hunting TTPs Continue to Shift After DarkSide Pipeline Attack
-
From Russia With… LockBit Ransomware- Inside Look & Preventive Solutions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor From Russia With… LockBit Ransomware- Inside Look & Preventive Solutions
-
LockBit 2.0 Interview with Russian OSINT
The original link failed its last check. Original publisher Detailsfor LockBit 2.0 Interview with Russian OSINT
-
LockBit 2.0 Interview with Russian OSINT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor LockBit 2.0 Interview with Russian OSINT
-
All Access Pass- Five Trends with Initial Access Brokers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor All Access Pass- Five Trends with Initial Access Brokers
-
Quick analysis of Haron Ransomware (feat. Avaddon and Thanos)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Quick analysis of Haron Ransomware (feat. Avaddon and Thanos)
-
Ransomware Gangs are Starting to Look Like Ocean’s 11
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware Gangs are Starting to Look Like Ocean’s 11
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor AvosLocker Ransomware
-
The Rise & Demise of Multi-Million Ransomware Business Empire
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Rise & Demise of Multi-Million Ransomware Business Empire
-
The First Step- Initial Access Leads to Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The First Step- Initial Access Leads to Ransomware
-
Cybercrime Featured Avaddon ransomware operation shuts down and releases decryption keys
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cybercrime Featured Avaddon ransomware operation shuts down and releases decryption keys
-
Avaddon ransomware shuts down and releases decryption keys
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Avaddon ransomware shuts down and releases decryption keys
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Avaddon Ransomware Analysis
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t12021
-
Phorpiex morphs- How a longstanding botnet persists and thrives in the current threat environment
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Phorpiex morphs- How a longstanding botnet persists and thrives in the current threat environment
-
Three major hacking forums ban ransomware ads as some ransomware gangs shut down
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Three major hacking forums ban ransomware ads as some ransomware gangs shut down
-
Darkside ransomware gang says it lost control of its servers & money a day after Biden threat
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Darkside ransomware gang says it lost control of its servers & money a day after Biden threat
-
The moral underground Ransomware operators retreat after Colonial Pipeline hack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The moral underground Ransomware operators retreat after Colonial Pipeline hack
-
Ransomware- Hunting for Inhibiting System Backup or Recovery
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware- Hunting for Inhibiting System Backup or Recovery
-
The original link failed its last check. Original publisher Detailsfor Intel 471
-
Avaddon RaaS - Breaks Public Decryptor, Continues On Rampage
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Avaddon RaaS - Breaks Public Decryptor, Continues On Rampage
-
W4 Jan - EN - Story of the week- Ransomware on the Darkweb
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor W4 Jan - EN - Story of the week- Ransomware on the Darkweb
-
Another ransomware (Avaddon) now uses DDoS attacks to force victims to pay
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Another ransomware (Avaddon) now uses DDoS attacks to force victims to pay
-
Avaddon Ransomware- Incident Response Analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Avaddon Ransomware- Incident Response Analysis
-
Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
-
The malware that usually installs ransomware and you need to remove right away
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The malware that usually installs ransomware and you need to remove right away
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q32020
-
Threat Hunting for Avaddon Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Hunting for Avaddon Ransomware
-
Leakware-Ransomware-Hybrid Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Leakware-Ransomware-Hybrid Attacks
-
What's behind the increase in ransomware attacks this year?
The original link failed its last check. Original publisher Detailsfor What's behind the increase in ransomware attacks this year?
-
How Ransomware Gangs Find New Monetization Schemes and Evolve in Marketing
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How Ransomware Gangs Find New Monetization Schemes and Evolve in Marketing
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q22020
-
Ransomware Report- Avaddon and New Techniques Emerge, Industrial Sector Targeted
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware Report- Avaddon and New Techniques Emerge, Industrial Sector Targeted
-
New Avaddon Ransomware launches in massive smiley spam campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Avaddon Ransomware launches in massive smiley spam campaign
-
Avaddon- From seeking affiliates to in-the-wild in 2 days
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Avaddon- From seeking affiliates to in-the-wild in 2 days
-
Ransomware Avaddon- principales características
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware Avaddon- principales características
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Exposing the UAE’s Underground Digital Dangers- The Attack Surface of One of the Most Digitally Advanced Countries in the Arab World
-
DarkSide Pipeline Attack Shakes Up the Ransomware-as-a-Service Landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DarkSide Pipeline Attack Shakes Up the Ransomware-as-a-Service Landscape
Newest first. Details opens the report in Explore.