NoEscape
NoEscape (canonical industry naming per Bleeping Computer + SOCRadar + Huntress + TheSecMaster tracking.
some sources also "No Escape" variant) is a suspected Avaddon successor rebrand Ransomware-as- a-Service operation active May/June 2023 through December 2023 exit scam with multi-extortion Windows + Linux + VMware ESXi multi-platform targeting; Russia-aligned organized cybercrime attribution via Bleeping Computer canonical July 2023 analysis + Michael Gillespie ID Ransomware canonical encryptor near-identity assessment ("NoEscape's and Avaddon's ransomware encryptors are almost identical, with only one notable change in encryption algorithms. Previously, the Avaddon encryptor utilized AES for file encryption, with NoEscape switching to the Salsa20 algorithm. Otherwise, the encryptors are virtually identical, with the encryption logic and file formats almost identical, including a unique way of 'chunking of the RSA encrypted blobs'") + Mandiant canonical Avaddon configuration file + directives analysis ("Avaddon and NoEscape encryptors use the same configuration file and directives") + SOCRadar canonical November 2024 Dark Web Profile + Huntress canonical December 2023 exit scam disclosure + TheSecMaster canonical March 2025 retrospective.
suspected operator continuity per Bleeping Computer ("some of the core Avaddon members are now part of the new ransomware operation")
standalone cluster paralleling bianlian + inc_ransom + base_8 in v0.1.148 post-Conti- takedown 2022-2024 RaaS fragmentation operators cell.
operational target profile North America + Europe primary geographic per Huntress + professional services + manufacturing + technology + construction primary sectors + cluster-defining CIS region victim exemption with free decryptors for CIS region (Avaddon-predecessor lineage signature + Russia-aligned ransomware ecosystem pattern)
operational attack architecture: (1) cluster-defining Avaddon-successor-suspected ransomware encryptor with nearly identical encryption logic + file formats + unique RSA encrypted blobs chunking method + identical configuration files + directives per Mandiant.
(2) cluster-defining ChaCha20 + Salsa20 encryption algorithm change from Avaddon's AES.
(3) cluster-defining Windows + Linux + VMware ESXi multi-platform targeting distinctive sophistication for 2023 RaaS.
(4) multi-extortion model with TOR data leak site per SOCRadar.
(5) recovery inhibition tradecraft per Bleeping Computer (shadow copy delete + WMIC shadowcopy delete + wbadmin delete systemstatebackup + vssadmin delete shadows + bcdedit recoveryenabled No commands)
(6) service termination tradecraft per Bleeping Computer (security software + backup applications + DB + web servers + QuickBooks + virtual machine platforms)
(7) cluster-defining ransom demands hundreds of thousands to $10M+ per Bleeping Computer enterprise-focused operation; (8) C++ from-scratch codebase claim per SOCRadar + TheSecMaster, unverified given Avaddon overlap evidence.
(9) cluster-defining December 2023 exit scam per Huntress ("The entire operation abruptly shut down in December 2023, with the threat actors disappearing after a suspected exit scam, leaving both affiliates and some victims in the lurch") + TheSecMaster ("reports emerged of a potential exit scam by the NoEscape operators, with affiliates claiming that ransom payments were being stolen and the operation's infrastructure was shut down"); (10) signature affiliate migration to LockBit post-exit-scam per TheSecMaster ecosystem migration tradecraft.
cluster fills the May-2023- onward + Avaddon-successor-suspected + multi- platform-Windows-Linux-ESXi + ChaCha20/Salsa20- encryption + CIS-exemption + December-2023-exit-scam + LockBit-affiliate-migration position in post- Conti-takedown 2022-2024 RaaS fragmentation operators cell.
canonical illustration of suspected Avaddon-successor-rebrand operator-relation + multi- platform RaaS sophistication + RaaS exit-scam case study + post-collapse affiliate ecosystem migration cited in essentially all subsequent ransomware operator industry analyses through 2023-2026 period.