2026-07-04NOTABLEAvalon framework chains a signed-binary MSBuild loader, ETW/AMSI patching and the CrownX ransomware payload in one implant
Avalon
tool · tool:avalon-malware-framework single-source
Modular Windows malware framework combining credential theft, lateral movement and the CrownX ransomware payload behind an LNK → MSBuild → ETW/AMSI-patching loader chain; assessed by Blackpoint Cyber as bearing hallmarks of AI-assisted development.
Aliases: CrownX
Coverage
1
first 2026-07-04 → last 2026-07-04
Latest activity
2026-07-04
Avalon framework chains a signed-binary MSBuild loader, ETW/AMSI patching and the CrownX ransomware payload…
Peak priority
notable
1 notable
Targets
·
no sector or region stated
Sources cited
2
2 hosts
Action items (4)
Do-now tasks recorded on the entries about Avalon, newest first. Check the date before acting on an older one.
- Block execution of MSBuild.exe, InstallUtil.exe and csc.exe via WDAC or AppLocker on all non-developer endpoints; these trusted developer utilities have no business running on a standard user workstation.2026-07-04Avalon framework chains a signed-binary MSBuild…
- Hunt for MSBuild.exe spawned by cmd.exe with a command line referencing a .tmp or .csproj file outside a build pipeline (Sysmon EID 1, ParentImage=cmd.exe, Image=MSBuild.exe).2026-07-04Avalon framework chains a signed-binary MSBuild…
- Disable automatic ISO/IMG mounting from mail clients and browser downloads, and alert on LNK files whose displayed icon does not match their target extension delivered inside a mounted image.2026-07-04Avalon framework chains a signed-binary MSBuild…
- Enforce Credential Guard and LSA protection to blunt the framework's credential-harvesting stage.2026-07-04Avalon framework chains a signed-binary MSBuild…
Defender insights
What each entry about Avalon tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (8 across 8 tactics)
8 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ExecutionScheduled Task/Job: Scheduled Task · Trusted Developer Utilities Proxy Execution: MSBuild
- PersistenceScheduled Task/Job: Scheduled Task
- Privilege EscalationScheduled Task/Job: Scheduled Task
- StealthTrusted Developer Utilities Proxy Execution: MSBuild
- Defense ImpairmentDisable or Modify Tools
- Credential AccessUnsecured Credentials: Credentials In Files · Credentials from Password Stores
- Lateral MovementRemote Services: SMB/Windows Admin Shares
- ImpactData Encrypted for Impact · Inhibit System Recovery
Execution TA0002
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-07-04/avalon-framework-msbuild-etw-loader-crownx-ransomware · ATT&CK page ↗
T1127.001Trusted Developer Utilities Proxy Execution: MSBuild×1
Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a software build platform used by Visual Studio. It handles XML formatted project files that define requirements for loading and building various platforms and configurations.
Evidence: 2026-07-04/avalon-framework-msbuild-etw-loader-crownx-ransomware · ATT&CK page ↗
Persistence TA0003
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-07-04/avalon-framework-msbuild-etw-loader-crownx-ransomware · ATT&CK page ↗
Privilege Escalation TA0004
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-07-04/avalon-framework-msbuild-etw-loader-crownx-ransomware · ATT&CK page ↗
Stealth TA0005
T1127.001Trusted Developer Utilities Proxy Execution: MSBuild×1
Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a software build platform used by Visual Studio. It handles XML formatted project files that define requirements for loading and building various platforms and configurations.
Evidence: 2026-07-04/avalon-framework-msbuild-etw-loader-crownx-ransomware · ATT&CK page ↗
Defense Impairment TA0112
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-07-04/avalon-framework-msbuild-etw-loader-crownx-ransomware · ATT&CK page ↗
Credential Access TA0006
T1552.001Unsecured Credentials: Credentials In Files×1
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.
Evidence: 2026-07-04/avalon-framework-msbuild-etw-loader-crownx-ransomware · ATT&CK page ↗
T1555Credentials from Password Stores×1
Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.
Evidence: 2026-07-04/avalon-framework-msbuild-etw-loader-crownx-ransomware · ATT&CK page ↗
Lateral Movement TA0008
T1021.002Remote Services: SMB/Windows Admin Shares×1
Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user.
Evidence: 2026-07-04/avalon-framework-msbuild-etw-loader-crownx-ransomware · ATT&CK page ↗
Impact TA0040
T1486Data Encrypted for Impact×1
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Evidence: 2026-07-04/avalon-framework-msbuild-etw-loader-crownx-ransomware · ATT&CK page ↗
T1490Inhibit System Recovery×1
Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.
Evidence: 2026-07-04/avalon-framework-msbuild-etw-loader-crownx-ransomware · ATT&CK page ↗
Entries about Avalon (1)
Where this entity is cited
Source distribution
- blackpointcyber.com1 (50%)
- thehackernews.com1 (50%)