Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution options included delayed scheduled tasks through DCOM, immediate scheduled tasks under the current identity, scheduled tasks created with a stolen token, and remote service execution described as PsExec style.
Opening the shortcut launched cmd.exe with delayed environment variable expansion enabled.
Execution options included delayed scheduled tasks through DCOM, immediate scheduled tasks under the current identity, scheduled tasks created with a stolen token, and remote service execution described as PsExec style.
Opaque arithmetic conditions, changing state values, randomized identifiers, and indirect string recovery surrounded this core logic.
Its version resources attempted to blend into Windows by presenting the executable as the Windows Management Instrumentation Provider Host, using values including Microsoft Corporation, Windows Management Instrumentation, WmiPrvSE, and WmiPrvSE.exe.
Once the response passed validation, the managed stage manually mapped the decrypted PE into the current process instead of writing it to disk and launching a new executable.
Avalon contained an anti-forensic cleanup subsystem designed to remove the Windows artifacts investigators would normally use to reconstruct the intrusion.
Once found, the project was copied to %TEMP%\ngen0cc9.dat, executed with the 64-bit .NET Framework build of MSBuild.exe, and deleted after execution.
Once found, the project was copied to %TEMP%\ngen0cc9.dat, executed with the 64-bit .NET Framework build of MSBuild.exe, and deleted after execution.
That inline task reconstructed strings at runtime, decoded a large Base64 blob, decrypted the resulting byte array, and loaded the recovered assembly through System.Reflection.Assembly.Load.
MSBuild supported inline C# through CodeTaskFactory, which allowed an XML project to compile and execute managed code inside a Microsoft signed development utility.
It contained a built-in password list including common and seasonal patterns such as Password1, Password123, P@ssw0rd, Admin123, Welcome1, Changeme1, Summer2024... Testing these values against local accounts allowed Avalon to convert weak credentials into reusable access.
Harvesting credentials, cookies, history, and bookmarks from Chromium-based browsers and Firefox.
Collecting data from cryptocurrency wallets, Windows Credential Manager, Discord, Slack, Teams, OpenVPN, WireGuard, saved RDP connections, SSH known hosts, Wi‑Fi profiles, and Group Policy Preferences cpassword artifacts.
The harvesting cluster referenced Chromium based browsers and Firefox, along with browser databases and artifacts such as Login Data, Cookies, History, Bookmarks, and Network\Cookies.
Execution options included delayed scheduled tasks through DCOM, immediate scheduled tasks under the current identity, scheduled tasks created with a stolen token, and remote service execution described as PsExec style.
Collecting data from cryptocurrency wallets, Windows Credential Manager, Discord, Slack, Teams, OpenVPN, WireGuard, saved RDP connections...
Beyond its credential theft, C2, and lateral movement functions, Avalon contained a dedicated ransomware and extortion function known as CrownX. This component handled the file encryption workflow, ransom note delivery, payment instructions, and the local recovery process.
Avalon contained functionality for terminating the Volume Shadow Copy Service, deleting shadow copies through COM, disabling VSS through registry changes, corrupting VSS metadata, removing related scheduled tasks... The recovery targeting logic also extended into Windows Recovery Environment and System Restore.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously unknown Windows post-exploitation malware framework delivered via phishing, password-protected archive, ISO, LNK, and MSBuild execution. It steals credentials and browser data, communicates with C2, loads payloads in memory, prepares lateral movement and remote execution, and sabotages recovery before deploying its ransomware component.
Avalon is a modular post-exploitation malware framework delivered via phishing and staged through an MSBuild-based in-memory chain. It combines credential theft, persistence, defense evasion, C2 communications, lateral movement, recovery sabotage, anti-forensic cleanup, and destructive disk access, while also embedding a ransomware component branded CrownX.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.