Avlj malware family
Avlj is a malware family tracked by MalwareAnalyzer by Cyble across 11 publicly analyzed samples. First seen 2026-08-13, most recently 2026-08-23. Observed ATT&CK techniques include T1059.001.
Corpus statistics
- Publicly analyzed samples: 11
- First seen: 2026-08-13
- Last seen: 2026-08-23
- Verdicts: malicious 11
- File types: pe 11
ATT&CK techniques used by Avlj
- T1059.001 - 11 samples
Recent Avlj samples
- f3dbc086a3e96c7a68d89b8ea54738d4cd0acfe70185b7f8e8a5f2ae8130832c - malicious (2026-08-23)
- 4c0d18224e45ff328ca8093de6f534734d8d6c5c07c2db522c9677a63762f2ca - malicious (2026-08-23)
- 71393ee85386702372e90ba2475838fa59801e64621397f8b47339829e17a307 - malicious (2026-08-22)
- 6d8fd7bace85485405458699230616dd64905f7657ac032503f0f89148128631 - malicious (2026-08-21)
- 4e9a6a433feb34e0a34813a9396d98602e4d36fe944391f6e5bc954ea0c2304c - malicious (2026-08-21)
- 1e87e8d4640c81b4121d347423e1e8941bbf3672dff35051c58e843d9a7ea969 - malicious (2026-08-18)
- 4111fc8ff506ed8a9f148fc1a1bea42d082eb5abb79200362a816698eb3487dc - malicious (2026-08-16)
- ed03f8d4c3e443e753c24e15941372063deef24afbcff356c0eb414e12d13e8d - malicious (2026-08-15)
- 72a3cd2a0776604e3f4072ca18a0e470bedcc6104a19fd98f70de7ed31aa9152 - malicious (2026-08-14)
- 885bf0d75869c084ca3e868fe42d7168c7cc9b32153b459b85a4da07a92be4c1 - malicious (2026-08-13)
- 1c34e55b7b9cac1150177dbc30af8ee98c4499ef837fba24c0066f16149dfafb - malicious (2026-08-13)
Frequently asked about Avlj
- What is Avlj?
- Avlj is a malware family tracked by MalwareAnalyzer by Cyble across 11 publicly analyzed samples. First seen 2026-08-13, most recently 2026-08-23. Observed ATT&CK techniques include T1059.001.
- How many Avlj samples have been analyzed?
- MalwareAnalyzer by Cyble holds 11 publicly analyzed samples attributed to Avlj, first seen 2026-08-13 and most recently 2026-08-23. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Avlj use?
- Across our Avlj samples the most frequently observed techniques are T1059.001 (11). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Avlj use?
- Avlj samples in this corpus are distributed as pe (11).
- Is Avlj malicious?
- 11 of 11 analyzed Avlj samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends