A newly observed malware framework uses a spoofed legal-document lure and a staged, fileless-oriented chain to hand off to CrownX ransomware capabilities.