Avenger is a Windows malware family used by the TICK espionage group, also known as BRONZE BUTLER and REDBALDKNIGHT, during Operation ENDTRADE. It functioned as a multi-stage downloader and selective backdoor delivery mechanism in intrusions targeting organizations in the defense, aerospace, chemical, and satellite sectors, particularly entities headquartered in Japan with subsidiaries in China.
Avenger performs host profiling before delivering follow-on payloads. Reported capabilities include identifying installed antivirus products, enumerating running processes with Tasklist, determining the compromised host’s domain, and collecting host volume information and operating system architecture. It can also browse files and directories on the victim system to gather additional targeting context. Based on this reconnaissance, the malware appears to support selective infection decisions aligned with campaign criteria.
The malware can decrypt files downloaded from command-and-control infrastructure and communicates over HTTP. In documented operations, if a host met targeting requirements, Avenger could retrieve an image containing malware concealed with steganography and extract a backdoor from it. Variants have also been observed injecting shellcode into svchost.exe, indicating use of process injection for execution and defense evasion. Multiple versions and target-specific variants have been identified, including a newer variant associated with the PDB string Avenger2 and a clearer internal code structure.
Avenger was delivered in a broader intrusion workflow that included spearphishing with compromised legitimate email accounts and stolen credentials. Its role within those operations was to assess victim suitability, stage additional payloads, and support covert post-compromise access while attempting to evade security controls.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Our analysis found that Avenger has a number of variants and versions depending on their targets... We found that the downloader has three stages... If the host doesn’t exist, Avenger will download an image with an embedded malware hidden via steganography and extract a backdoor.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
If the host doesn’t exist, Avenger will download an image with an embedded malware hidden via steganography and extract a backdoor.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... Avenger ... (v1.1→v1.2) ...
Avenger (v1.1→v1.2)
Malware capable of injecting shellcode into svchost.exe.
Identifies the domain of compromised hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.