During C0018, the threat actors ran nslookup and Advanced IP Scanner on the target network.3
campaign
C0018 C0018
- First seen
- February 2022
- Last seen
- March 2022
- Created
- 17 January 2023
- Last modified
- 31 July 2026
C0018 was a month-long ransomware intrusion that successfully deployed AvosLocker onto a compromised network. The unidentified actors gained initial access to the victim network through an exposed server and used a variety of open-source tools prior to executing AvosLocker.[1][2]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference C0018
During C0018, the threat actors opened a variety of ports to establish RDP connections, including ports 28035, 32467, 41578, and 46892.4
During C0018, the threat actors used Base64 to encode their PowerShell scripts.56
During C0018, the threat actors collected whoami information via PowerShell scripts.7
During C0018, AvosLocker was disguised using the victim company name as the filename.8
For C0018, the threat actors renamed a Sliver payload to vmware_kb.exe.9
Standing C0018
Reach is how much of ATT&CK this campaign touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 56 ATT&CK campaigns only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
55th percentile · 55% of 56 ATT&CK campaigns have this many Enterprise techniques or fewer.
48th percentile · 52% of 56 ATT&CK campaigns have more tactics spanned.
88th percentile · 88% of 56 ATT&CK campaigns have this many tools and malware or fewer.
55% of the population shares a single value across only 3 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
93rd percentile · 93% of 56 ATT&CK campaigns have this many detection rules per technique or fewer.
Detection coverage C0018
1160 distinct rules cover the 19 techniques recorded for this campaign. The 1223 technique-to-rule mappings resolve to 1160 distinct rules, because one rule can cover several techniques. 819 Sigma · 341 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org