/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Avaddon ransomware gang releases decryption keys for 2,934 of its victims and is likely shutting down due to increased scrutiny by governments around the world

The Avaddon ransomware gang has shut down operation and released the decryption keys for their victims to BleepingComputer.com.

BleepingComputer Lawrence Abrams

Context & Ripple Effects

Avaddon's exit follows a playbook the ecosystem has seen before: when the developers of TeslaCrypt shut down in 2016 they also released a master key so victims could decrypt for free. What has changed since is the stated cause — Avaddon attributes its shutdown to increased scrutiny by governments worldwide, not internal factors.

The shutdown lands mid-escalation on that front: months later BlackMatter would announce its own closure citing 'pressure from the authorities', and Conti would pull infrastructure offline while its leaders regrouped under other brands. Avaddon had also already imposed rules barring affiliates from hitting government, healthcare, education and charity targets — a sign the brand was managing political heat before abandoning it.

First-order effects

  • The 2,933 other victims alongside BleepingComputer's readers can now recover files for free instead of negotiating ransoms — the immediate value flows to victims who never paid or are still deciding.

Second-order effects

  • Affiliates renting Avaddon's malware must migrate to rival brands, following the pattern AdvIntel described when Conti went dark and its leaders partnered with smaller groups — demand for ransomware-as-a-service capacity doesn't disappear, it relocates.

Third-order effects

  • If government pressure keeps forcing brand shutdowns, the industry structure shifts toward disposable brands that rebrand rather than retire, with law-enforcement seizures like the LockBit key recovery becoming a recurring cleanup mechanism after each exit.

The trend: Ransomware operations are entering a cycle where sustained government pressure forces brands to shut down and rebrand, leaving victims with free decryption and affiliates shopping for new platforms.

Discussion

  • @emsisoft @emsisoft on x
    We've just released a decryptor for #Avaddon #ransomware. https://www.emsisoft.com/...
  • @rpargman Randy Pargman on x
    Thanks @LawrenceAbrams for this awesome news. Friday just got a little better! https://www.bleepingcomputer.com/ ... Thanks @demonslay335 for verifying it and @emsisoft for working on the decryptor. You all rock!
  • @gossithedog Kevin Beaumont on x
    It's thought the average victim payment was about $600k, with 3000 of so impacted orgs they made some money. EMSIsoft have a free decryptor out now, for the late running victim orgs. https://twitter.com/...
  • @josephmenn Joseph Menn on x
    Ransomware group Avaddon may have quit. A lot of churn ahead of the Putin summit. https://www.bleepingcomputer.com/ ...
  • @campuscodi Catalin Cimpanu on x
    Avaddon ransomware operation shuts down and releases decryption keys for 2,934 past victims https://therecord.media/... https://twitter.com/...