Avalon Malware Framework Packs CrownX Ransomware and EDR-Killing Evasion

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
Jul 6, 2026
2 min read

Researchers have documented a previously undocumented modular malware framework codenamed Avalon that bundles a full ransomware payload internally named CrownX. Rather than a single-purpose tool, Avalon combines credential theft, lateral movement, remote access, recovery disruption and ransomware execution under one umbrella — and runs almost entirely in memory to stay invisible to conventional endpoint detection, according to research covered by The Hacker News.

The delivery chain

The intrusion begins with a spoofed legal-document email pointing to a password-protected archive on Proton Drive. The malicious content is embedded inside an ISO image rather than attached directly, sidestepping email-layer scanning; from there a shortcut (LNK) file and MSBuild launch the payload. It is a textbook living-off-the-land chain — legitimate Windows tooling doing illegitimate work — and every stage executes in memory to minimise disk artefacts.

Built to defeat your EDR

What sets Avalon apart is an extensive defence-evasion subsystem that specifically targets major endpoint security products — Microsoft Defender, SentinelOne, CrowdStrike, Sophos, Elastic Endpoint, FortiEDR, ESET and McAfee are all named. Before deploying CrownX, the framework steals credentials, browser data and wallet data, moves laterally, and disrupts backup and recovery systems so victims cannot simply restore their way out. This is the same “destroy the backups first” playbook that turns a recoverable incident into a payment decision.

The India angle

  • Backup disruption defeats the standard defence — “we have backups” is the reassurance most Indian SMEs offer regulators. Avalon targets recovery systems directly, so untested or network-reachable backups are no defence at all.
  • EDR is necessary but not sufficient — the named products are widely deployed across Indian BFSI and GCCs. A framework engineered to blind them argues for defence in depth: segmentation, offline backups, and behavioural monitoring beyond the agent.
  • Ransomware plus data theft is a dual-report event — credential and wallet theft alongside encryption means both a CERT-In cyber-incident report (6 hours) and, where personal data is involved, a DPDP breach notification.

What security teams should do now

Assume email lures will reach inboxes and design for the click: block ISO and LNK auto-execution, and alert on MSBuild spawning from user directories. Verify your backups are genuinely offline or immutable and test a restore — an untested backup is a hope, not a control. Watch for EDR agents going quiet, which is itself a signal. When encryption is paired with credential and wallet theft, run your integrated breach playbook for both the security-incident and data-protection reporting tracks. Avalon is also further proof of AI-accelerated tooling maturity — see our coverage of the first LLM-agent-operated ransomware.

Worried about your exposure?

Get a free attack-surface review

We check what an attacker would see about your business — leaked credentials, exposed services, dark-web mentions. 30 minutes, no obligation.

Book exposure review Replies in 4 working hrs · India-only · Senior consultants