Skip to content
skopnix
← adversaries
Crime

noescape

ransomware.liverefreshed 2026-09-15

sigil

Analyst brief

NoEscape was a RaaS operation active from May to December 2023 believed to be a rebrand of the defunct Avaddon ransomware, targeting professional services, manufacturing, and healthcare with triple-extortion capabilities (encryption, data theft, and optional DDoS), before abruptly shutting down in an apparent exit scam.

Take it with you
References
Early access

Track noescape on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected