C0018 last observed
The campaign source marks this as the latest known activity date.
C0018 was a month-long ransomware intrusion that successfully deployed AvosLocker onto a compromised network. The unidentified actors gained initial access to the victim network through an exposed server and used a variety of open-source tools prior to executing AvosLocker.
Each relationship retains its own confidence and source.
Every date says what it measures so catalog dates are not confused with publication dates.
CVEs, techniques, malware, and indicators in the sections below are associated with an attributed actor. They are useful investigative context, but the campaign source does not necessarily link every item directly to this campaign.
Use this material to guide hunting and prioritization, then confirm each relationship against its cited source.
No linked CVEs are available.
No linked techniques are available.
No linked malware or tools are available.
No source-linked indicators are available.
Open the original material before making an attribution or response decision.