Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More
New: 2026 Gartner® Market Guide for Adversarial Exposure Validation
Learn More
New Research: Exploiting Configuration Trust in AI Coding Tools
Learn More
New Case Study: How a Financial Authority Validates Cyber Resilience
Learn More

AvosLocker Ransomware Abuses Driver File to Disable AV and Scans for Log4shell

May 9, 2022

According to the analysis, the suspected entry point is via the Zoho ManageEngine ADSelfService Plus (ADSS) exploit. Due to the lack of network traffic details, TrendMicro could not identify the exact CVE ID of the security gap the attacker used. However, there are some indications that they abused the same vulnerability previously documented by Synacktiv during a pentest, CVE-2021-40539. The gap they observed was particularly similar to the creation of JSP files (test.jsp), execution of keytool.exe with "null" parameters to run a crafted Java class/code.