Avalanche was a prolific cybercriminal operation active from late 2008 and associated both with a major phishing gang and with the resilient criminal infrastructure used to host and distribute malicious content. It became one of the most significant phishing threats on the Internet in 2009, accounting for roughly two-thirds of observed global phishing activity during the second half of that year. The operation used automated tooling to mass-produce spoofed websites and spam campaigns, targeted banks and online service providers, and increasingly shifted from credential-harvesting phishing toward delivery of the Zeus banking Trojan. Victims included small and midsized businesses, which suffered theft of banking credentials and subsequent fraudulent transfers. Avalanche was notable for its use of fast-flux and double fast-flux techniques, botnet-backed proxying, and rapidly changing infrastructure that complicated takedown efforts and made it attractive as a communications and hosting layer for other criminal malware operations. Over time, the infrastructure was linked to numerous major malware families, including banking Trojans, remote-access malware, and ransomware such as Zeus, GOZeuS, Citadel, Dridex, Vawtrak, Qbot, Bebloh, Nymaim, TeslaCrypt, and Ransomlock. It also supported money-muling activity and served as a fast-flux communications platform for other botnets. Researchers and law enforcement assessed Avalanche as a highly sophisticated financially motivated criminal enterprise, widely believed to have operated from Eastern Europe. Coordinated anti-phishing actions in 2009 and 2010 reduced the uptime and volume of its phishing campaigns, but the broader infrastructure remained active for years. A major international law-enforcement operation led by German authorities and supported by partners in more than 40 countries disrupted Avalanche in 2016 through large-scale sinkholing, domain seizure, and arrests. The operation was described as one of the largest botnet takedowns conducted against criminal infrastructure of this type.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phishing operations targeting banks, online service providers, and small and midsized businesses, including spoof sites and spam lures delivering Zeus to steal banking credentials and enable fraudulent ACH and wire transfers.
Avalanche appears only in a generic Wikipedia navigation list of hacking groups, without any discussion tying it to the PoisonIvy content.
A cybercriminal botnet infrastructure used since 2009 for money muling schemes, distributing a wide variety of malware, and providing fast-flux communication infrastructure for other botnets and malware operations.
Groups Anonymous associated events Avalanche Crime Boys GNAA Goatse Security Insanity Zine Corp. GhostNet Level Seven PLA Unit 61398 Prime Suspectz RBN ShadowCrew World of Hell Sandworm
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.