Xswkit is a malware family identified in reporting on the Avalanche criminal infrastructure. High-confidence source material places Xswkit among roughly 20 malware families hosted or distributed through Avalanche, a large global cybercriminal platform active since at least 2009 and dismantled in November 2016 by an international law-enforcement operation. Avalanche used fast-flux and double fast-flux techniques, phishing campaigns, spam, and compromised proxy systems to conceal backend infrastructure and distribute malware, primarily affecting Microsoft Windows systems. In the cited reporting, Xswkit is not described with family-specific technical behavior beyond its association with Avalanche. The broader Avalanche ecosystem was used against more than 40 major financial institutions and supported credential theft, theft of banking and credit-card data, unauthorized remote access, malware propagation, denial-of-service activity, and in some cases ransomware and money mule schemes; however, these capabilities are attributed to Avalanche-associated malware generally, not specifically to Xswkit. No Xswkit-specific infection vector, threat actor attribution, targeted sector, or indicators of compromise are directly provided in the content beyond its hosting/distribution via Avalanche.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The criminal groups have been using the Avalanche infrastructure since 2009 for conducting malware, phishing and spam activities. They sent more than 1 million e-mails with damaging attachments or links every week to unsuspecting victims.
Sinkholing is an action whereby traffic between infected computers and a criminal infrastructure is redirected to servers controlled by law enforcement authorities... infected computers can no longer reach the criminal command and control computer systems and so criminals can no longer control the infected computers.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family delivered via Avalanche and associated in this context with credential theft and banking fraud activity.
Malware family hosted on Avalanche infrastructure; associated generally with credential theft and malicious activity.
The following malware families were hosted on Avalanche: ... Xswkit
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.