Cybersecurity researchers have unveiled a sophisticated, previously undocumented modular malware framework codenamed Avalon, which is being disseminated through a highly evasive multi-stage phishing campaign designed to circumvent conventional security protocols. This discovery, detailed by Blackpoint Cyber researchers Nevan Beal and Sam Decker, marks a significant escalation in the cyber threat landscape, particularly due to the framework’s comprehensive capabilities and the subtle but discernible signs of artificial intelligence assistance in its development. The emergence of Avalon, alongside other recent findings of AI-driven agentic ransomware and codeless LLM-powered malware, underscores a critical shift where advanced attack methodologies are becoming more accessible and potent, challenging traditional notions of threat actor sophistication.
Unveiling Avalon: A Modular Menace with Broad Capabilities
Avalon represents a formidable new entrant into the realm of advanced persistent threats (APTs), distinguishing itself through its modular design and a broad spectrum of integrated functionalities. At its core, Avalon is engineered to facilitate credential harvesting, enable lateral movement within compromised networks, establish persistent remote access, disrupt recovery mechanisms, and ultimately deploy its ransomware component, internally named CrownX. This consolidation of diverse malicious functions under a single framework illustrates a strategic move by threat actors to streamline their operations, making their campaigns more efficient and impactful.
The initial phase of the Avalon attack chain is a meticulously crafted phishing expedition. Victims receive spoofed legal documents, a common social engineering tactic designed to induce urgency and trust. Crucially, these emails do not directly attach malicious executables, a tactic that would typically trigger immediate detection by email security gateways. Instead, they direct recipients to password-protected archives hosted on cloud storage services like Proton Drive. This method leverages legitimate services and obfuscates the malicious payload, effectively bypassing initial email-layer security controls that scan for known malware signatures or suspicious attachments.
Once the archive is accessed, the next layer of evasion comes into play. The malicious content is embedded within an ISO image, a disk image file format. ISO images, when mounted, appear to the operating system as a legitimate CD or DVD drive. This technique is increasingly favored by threat actors because it allows them to package multiple files, including malicious executables, without triggering many endpoint detection and response (EDR) systems that might scrutinize standalone executable attachments. Within this mounted ISO image, victims encounter a seemingly innocuous document-themed Windows Shortcut file, such as "Secure Document CA-2833505.pdf.lnk." The ".lnk" extension, often hidden by default in Windows Explorer, masks the true nature of the file.
Interacting with this shortcut initiates a complex, staged malware sequence. The shortcut is configured to execute a command that launches an MSBuild project located within the ISO image. MSBuild, a Microsoft build engine, is a legitimate development tool used for compiling applications. Its abuse by attackers is a known technique (often referred to as "living off the land" or "LOLBIN") that allows them to execute malicious code using trusted system binaries, further complicating detection.
The MSBuild project then loads an embedded .NET assembly. This assembly is designed to perform a critical evasive maneuver: it interferes with the regular functioning of Event Tracing for Windows (ETW). ETW is a powerful, high-performance tracing facility built into Windows that allows applications to log kernel or application-defined events. Security tools often rely on ETW to collect telemetry and detect suspicious activities. By disrupting ETW, Avalon significantly reduces its forensic visibility, making it harder for security analysts to trace its actions and for EDR solutions to monitor its behavior. Following this disruption, the .NET assembly proceeds to download the next-stage payload, responsible for launching the full Avalon framework, over an encrypted HTTPS channel, further masking its command-and-control (C2) communications.
Comprehensive Defense Evasion and Modular Capabilities
A defining characteristic of Avalon is its extensive defense evasion subsystem. This framework is specifically engineered to elude detection by a wide array of leading cybersecurity tools. Researchers noted that Avalon incorporates bespoke methods to conceal its execution from solutions associated with industry giants such as Microsoft Defender, SentinelOne, CrowdStrike, Sophos, Elastic Endpoint, FortiEDR, ESET, McAfee, and Bitdefender. This sophisticated level of evasion is not trivial; it implies a deep understanding of how these security products operate and their detection mechanisms.

The researchers elaborated that these capabilities empower Avalon with "a multitude of ways to reduce telemetry, bypass user mode monitoring, and adjust its execution depending on the defensive controls present on the host." This adaptive evasion allows Avalon to tailor its behavior based on the specific security environment it encounters, making it exceptionally resilient. By reducing telemetry, it limits the data available for security analysts to investigate. Bypassing user mode monitoring means it can operate below the radar of many EDR solutions that primarily monitor user-level processes.
The complete set of features integrated into Avalon underscores its versatility and destructive potential:
- Credential Collection: Designed to harvest sensitive login information from compromised systems, enabling broader access.
- Lateral Movement: Mechanisms to spread across a network from an initial foothold, compromising additional systems.
- Remote Access: Establishes persistent backdoors for long-term control over infected machines.
- Recovery Disruption: Targets backup systems and shadow copies to prevent data restoration, increasing the pressure for ransom payment.
- Ransomware Execution (CrownX): The final stage, encrypting critical data and demanding a ransom.
Blackpoint Cyber highlighted that "CrownX represented the final extortion stage, but the damage extended well beyond the encryption itself." By the time the ransom note manifests, the broader Avalon framework has already executed a cascade of malicious activities: credentials have been exfiltrated, robust command-and-control (C2) communications have been established, multiple avenues for lateral movement have been prepared, and crucial local recovery options have been systematically weakened. This comprehensive approach means that even if the ransom is paid or data is recovered from backups, the underlying compromise and potential for future attacks remain a severe threat.
The AI Fingerprint: Lowering the Barrier to Entry
Perhaps one of the most concerning aspects of Avalon’s discovery is the strong evidence suggesting artificial intelligence-assisted development. Researchers observed that the framework appears to have been assembled using multiple components, displaying a "scant regard for sophisticated tradecraft or operational security." This seemingly contradictory observation—a highly capable framework developed with less attention to traditional, meticulous operational security—points towards the use of AI. Building such a multi-functional, evasive framework traditionally requires significant expertise, time, and resources.
The findings indicate how AI can drastically lower the barrier to entry for malware development. It enables actors with limited technical expertise and resources to generate complex tools that would otherwise demand extensive development effort. This phenomenon fundamentally alters how the cybersecurity community assesses threat actors; the presence of sophisticated capabilities is no longer a reliable indicator of a group’s operational maturity or deep technical prowess. AI can effectively democratize advanced cyber warfare tools, putting them within reach of a wider range of malicious actors, from less experienced individuals to state-sponsored groups looking to accelerate their operations.
The Rise of Agentic Ransomware: JADEPUFFER’s Automated Threat
The revelations about Avalon coincide with other groundbreaking reports illustrating the profound impact of AI on cybercrime. Sysdig recently detailed what it described as the first publicly documented agentic ransomware infection driven by a large language model (LLM) from inception to conclusion. This advanced threat actor, codenamed JADEPUFFER, demonstrated the ability to dynamically retry and tweak its actions in real-time to achieve its malicious objectives.
According to Sysdig’s Michael Clark, the JADEPUFFER operator gained initial access to an internet-facing Langflow instance by exploiting CVE-2025-3248. Langflow, an open-source visual LLM orchestration framework, likely became a target due to misconfigurations or vulnerabilities, allowing the attacker to inject malicious prompts or gain control. From this initial foothold, JADEPUFFER launched an "adaptive and fully automated campaign," pivoting to the intended target and executing a destructive database-extortion playbook against the victim’s production database server.
This incident highlights the concept of "LLMjacking," where attackers leverage stolen credentials or compromised AI models to execute their campaigns, potentially reducing the financial cost of operations to "close to zero." The implication is stark: "The skill floor for running ransomware has dropped to whatever it costs to run an agent." This means that the need for human intervention in complex attack chains can be significantly reduced, allowing AI agents to autonomously identify vulnerabilities, adapt to defenses, and execute payloads, making attacks faster, more persistent, and harder to detect in real-time.

Codeless Command and Control: LLMs Transform Attack Mechanics
Further cementing the trend of AI integration in cyberattacks is the discovery by Palo Alto Networks Unit 42 of an AI malware that combines a Telegram bot with a public LLM API to facilitate a codeless attack. This innovative malware, uploaded to VirusTotal on March 11, 2026, and notably showing zero detections across all engines at the time of its discovery, represents another alarming development.
Upon execution, the implant transmits basic system details to the attacker’s Telegram bot, subsequently entering a command-and-control (C2) loop. In this loop, it polls the Telegram bot API every five seconds for new messages. The genius of this malware lies in its operational simplicity for the attacker: each operator message, written in natural language, is forwarded to a public LLM API endpoint (e.g., "api.groq[.]com/openai/v1/chat/completions"). The LLM then translates these natural language instructions into their equivalent shell commands, which are subsequently executed on the victim’s system. The results of these command executions are then exfiltrated back to the attacker via the same Telegram channel.
Palo Alto Networks Unit 42 emphasized that this "LLM translation layer replaces shell syntax with plain text." The attacker merely types plaintext instructions into Telegram, the LLM translates them into executable shell commands, and the victim’s system executes them. The critical takeaway is that "No command-line knowledge is required" for the attacker. This drastically expands the pool of potential cybercriminals, allowing individuals without specialized technical skills in scripting or command-line interfaces to orchestrate sophisticated attacks by simply issuing natural language commands. This abstraction layer lowers the cognitive load for attackers and makes it easier for them to manage and scale their operations.
Broader Implications for Cybersecurity
The emergence of Avalon, JADEPUFFER, and the codeless AI malware signals a fundamental shift in the cyber threat landscape. The traditional arms race between attackers and defenders is now being redefined by the pervasive integration of artificial intelligence.
- Democratization of Advanced Attacks: AI tools are lowering the entry barrier for cybercrime, enabling less skilled actors to launch sophisticated campaigns. This means a potential surge in the volume and complexity of attacks from a wider range of threat actors.
- Adaptive and Autonomous Threats: Agentic ransomware like JADEPUFFER demonstrates the potential for fully automated, adaptive attacks that can dynamically respond to environmental changes and defensive measures without constant human oversight. This accelerates attack timelines and reduces detection windows.
- Enhanced Evasion Capabilities: AI can be used to generate novel malware variants, craft highly convincing phishing lures, and develop adaptive evasion techniques that are more difficult for signature-based and even behavioral detection systems to identify. Avalon’s targeted evasion of multiple EDRs is a prime example.
- Challenges for Attribution: As AI assists in generating code and orchestrating attacks, attributing attacks to specific human actors or groups becomes increasingly complex. The "AI fingerprint" might obscure traditional indicators of compromise (IOCs) associated with particular threat groups.
- Increased Speed and Scale of Attacks: LLMs can generate phishing emails, malicious code snippets, and exploit scripts at an unprecedented speed, allowing attackers to scale their operations rapidly and launch more frequent, tailored attacks.
Defensive Strategies in an Evolving Landscape
In light of these escalating threats, organizations must reassess and enhance their cybersecurity posture. A multi-layered, adaptive defense strategy is no longer optional but imperative:
- Advanced Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR): Investing in EDR/XDR solutions with strong behavioral analysis and AI-driven threat intelligence is crucial to detect the subtle indicators of compromise that Avalon-like frameworks exhibit. These systems must be capable of detecting "living off the land" techniques and anomalous process execution.
- Proactive Threat Hunting: Security teams need to adopt a proactive threat hunting mindset, actively searching for signs of compromise rather than solely relying on automated alerts. This includes monitoring for ETW tampering, unusual MSBuild processes, and suspicious network connections.
- Robust Email and Web Security Gateways: While initial phishing may bypass some controls, advanced gateways that perform deep content inspection, URL reputation analysis, and sandbox suspicious attachments (including ISO files) are vital. User education on identifying sophisticated phishing attempts remains a foundational defense.
- Identity and Access Management (IAM): Implementing strong authentication (MFA), least privilege principles, and continuous monitoring of user behavior can mitigate the impact of credential theft, a primary objective of Avalon.
- Regular Backups and Disaster Recovery: Comprehensive, immutable backups stored offline or in secure, segregated environments are the last line of defense against ransomware attacks like CrownX. Regular testing of disaster recovery plans is essential.
- Security Awareness Training: Educating employees about the latest phishing techniques, the dangers of interacting with suspicious links or attachments (even in password-protected archives), and the importance of reporting anomalies is paramount. Training should specifically address the evolving nature of social engineering.
- Patch Management and Vulnerability Management: Regularly patching systems and applications, especially those that are internet-facing or widely used (like Langflow instances), is critical to close known attack vectors like CVE-2025-3248.
- AI for Defense: While AI fuels new attacks, it also offers powerful defensive capabilities. Organizations should explore leveraging AI-powered security tools for anomaly detection, threat intelligence correlation, and automated incident response to combat AI-driven threats effectively.
In conclusion, the discovery of Avalon and the concurrent emergence of agentic and codeless AI-powered malware underscore a transformative moment in cybersecurity. The traditional boundaries of threat actor capabilities are blurring, and the speed and adaptability of attacks are increasing exponentially. Organizations and individuals alike must recognize this evolving threat landscape and adopt proactive, multi-faceted defensive strategies to safeguard against the sophisticated, AI-driven cyber threats that are now becoming the new normal. The "kill chain" described by Blackpoint Cyber, from a familiar business lure to a multi-capability framework designed for extensive compromise and extortion, serves as a stark reminder of the urgent need for heightened vigilance and adaptive security measures in this new era of AI-powered cyber warfare.
