{
  "Event": {
    "analysis": "1",
    "date": "2026-07-02",
    "extends_uuid": "",
    "info": "[Threat Intel] Vibe Coded Extortion: Path from Legal Lure to CrownX Ransom Capabilities",
    "protected": false,
    "publish_timestamp": "1784200128",
    "published": true,
    "threat_level_id": "3",
    "timestamp": "1784200127",
    "uuid": "477b481a-0222-44c4-9bce-e0eddb59c52a",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#705cef",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Scheduled Task - T1053.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Disk Structure Wipe - T1561.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#ed66f6",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"",
        "relationship_type": ""
      },
      {
        "colour": "#51b040",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"InstallUtil - T1218.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#5539fe",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#041edc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"SMB/Windows Admin Shares - T1021.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#8ed4a7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Clear Windows Event Logs - T1070.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#07ff3c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"LSASS Memory - T1003.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#461928",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Indicator Blocking - T1562.006\"",
        "relationship_type": ""
      },
      {
        "colour": "#e43954",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#59699c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#36d931",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"",
        "relationship_type": ""
      },
      {
        "colour": "#30cc3b",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"File Deletion - T1070.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#3c0f50",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Software Packing - T1027.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#5884a7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#cb2c9b",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Dynamic-link Library Injection - T1055.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#297c25",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#110041",
        "local": false,
        "name": "rectifyq:sub-category=\"malware-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783076423",
        "to_ids": false,
        "type": "link",
        "uuid": "e65d3b35-61bb-4683-9d8b-0857b13914ab",
        "value": "https://blackpointcyber.com/blog/avalons-path-from-legal-lure-to-crownx-ransom-capabilities/",
        "Tag": [
          {
            "colour": "#6b003a",
            "local": true,
            "name": "workflow:todo=\"create-missing-misp-galaxy-cluster\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783076423",
        "to_ids": false,
        "type": "text",
        "uuid": "481ca573-431b-46cb-9d12-7a39894a5797",
        "value": "A sophisticated multi-stage phishing campaign delivers a previously undocumented framework called Avalon through spoofed legal documents hosted on Proton Drive. The intrusion begins with password-protected archives containing ISO images that execute malicious MSBuild projects, loading payloads entirely in memory without conventional executable attachments. Avalon consolidates credential theft, lateral movement, recovery disruption, and ransomware capabilities within a single framework, with its encryption component branded as CrownX. The framework demonstrates hallmarks of AI-assisted development, rapidly combining multiple post-exploitation capabilities that previously required sustained development effort. Avalon targets browsers, cryptocurrency wallets, messaging platforms, VPN configurations, and infrastructure systems while implementing extensive defense evasion techniques against major security products. The framework disrupts recovery by eliminating Volume Shadow Copies, Windows Recovery Environment..."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783076423",
        "to_ids": false,
        "type": "text",
        "uuid": "83109290-8d26-44e6-8139-70ada087a394",
        "value": "Name: Vibe Coded Extortion: Path from Legal Lure to CrownX Ransom Capabilities\nAuthor: AlienVault\nAdversary: \nTags: [\"ransomware\", \"credential theft\", \"lateral movement\", \"avalon\", \"defense evasion\", \"phishing\", \"crownx\", \"ai-assisted development\"]\nTgtd countries: []\nMlwr families: [\"Avalon\", \"CrownX\"]\nAttack_ids: [\"T1053.005\", \"T1561.002\", \"T1539\", \"T1218.004\", \"T1566.001\", \"T1140\", \"T1021.002\", \"T1555.003\", \"T1070.001\", \"T1003.001\", \"T1562.006\", \"T1562.001\", \"T1078\", \"T1027\", \"T1486\", \"T1070.004\", \"T1027.002\", \"T1204.001\", \"T1055.001\", \"T1490\"]\nIndustries: []"
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check: 16/07/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784154159",
        "to_ids": true,
        "type": "md5",
        "uuid": "e7ae6638-dfda-4943-ad95-bc9802cad358",
        "value": "c3587edc48c37656b29bcd3da9458eea",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check: 16/07/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784154159",
        "to_ids": true,
        "type": "sha256",
        "uuid": "893abd12-4d5b-4dd7-91a0-0a4e2b90a280",
        "value": "4b7301f02b8312ae6de614981f325dbbabee32166630618fdff74615d9a487ba",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check: 16/07/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784154160",
        "to_ids": true,
        "type": "sha256",
        "uuid": "1003a5b1-800d-414a-8109-644a1a82c190",
        "value": "59a260716d05c20229c6a46fe0a2fb5b80fa30c9c73a850222d9d3454426a60a",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check: 16/07/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784154162",
        "to_ids": true,
        "type": "sha256",
        "uuid": "f86de9c1-f875-49ba-877e-463adeab1f26",
        "value": "607cb58b8a592885eef5cfbe35ddce962741b0775c575f58cb3a96ca0ee893a6",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check: 16/07/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784154163",
        "to_ids": true,
        "type": "sha256",
        "uuid": "600ac2d8-66a5-406d-8d08-11c35ba1de5f",
        "value": "adbc18f15019ef2ba6890b7996445c14350d57ba772eb33182889bc14ac47085",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check: 16/07/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784154164",
        "to_ids": true,
        "type": "sha256",
        "uuid": "41d81a73-f70e-47c5-8513-134d80162227",
        "value": "b7d50d0406afcd2efd87bf3bf8c4211719ba9817dd2e0ad62af10c933e765e28",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check: 16/07/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784154165",
        "to_ids": true,
        "type": "sha256",
        "uuid": "b464b5bf-40a0-4ed0-a63a-d111a545bd36",
        "value": "c725815cbb07ab5be8903e74ef8aea46ef9c25e4a3bc626ae94bfc1ae21df6e3",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check: 16/07/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784154166",
        "to_ids": true,
        "type": "sha256",
        "uuid": "b0ff3ff6-cb65-4e10-a605-15987610b0ed",
        "value": "e3ec5926a167d6e3359f98cdfb7ac3b2cce97652843056505d02e6d2898573c6",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784156814",
        "to_ids": true,
        "type": "url",
        "uuid": "b27ef47e-2479-453e-b384-0227dadcf54f",
        "value": "https://helloxcherry.com/cdn/static/c3587edc48c37656b29bcd3da9458eea/update",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784156836",
        "to_ids": true,
        "type": "domain",
        "uuid": "6c356602-55ed-48af-896c-d34a9e433375",
        "value": "helloxcherry.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Financial fraud",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784151696",
        "to_ids": true,
        "type": "btc",
        "uuid": "6b28c02f-0439-460b-8532-af7bafec12ad",
        "value": "bc1qq9tx6p99jpqcj9p6nr3mwc3f9q3sxmj45l4anz"
      }
    ]
  }
}