New Avalon Malware Framework Packs CrownX Ransomware Capabilities

2026-07-03T19:24:07Zee170a79e9b6c200c49e90a95ad48d7749bea330390100cd6f7e46cb0efdd31b
active-exploitationai-agent-attackcredential-theftespionagemacOS-stealermalwaremodular-malwarenpm-supply-chainphishingprompt-injectionransomwareresidential-proxyspywaresupply-chain-credentialsvulnerability

What happened

A surge of high-impact activity: researchers uncovered Avalon, a modular malware framework that delivers credential theft, lateral movement and CrownX ransomware via multi-stage phishing; North Korea-linked malicious npm packages impersonating Rollup polyfills to steal developer secrets; targeted campaigns (Armored Likho, ToddyCat/Umbrij, VEIL#DROP, PamStealer, ChocoPoC) delivering stealers, RATs and API-based email exfiltration; and mass credential theft (FortiBleed) tied to ransomware groups. Multiple high-severity vulnerabilities are in active use or being added to KEV — notably SharePointR

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
ee170a79e9b6c200c49e90a95ad48d7749bea330390100cd6f7e46cb0efdd31b
Enrichment time
2026-07-03T19:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · New Avalon Malware Framework Packs CrownX Ransomware Capabilities · Baitaphish