< Back to all clusters
[TECHNOLOGY] · United States · 2 sources

started · updated

AvisLoader malware uses P2P network to evade takedowns

Cybersecurity researchers at Varonis Threat Labs have identified a new Windows malware loader named AvisLoader. The malware is designed to resist traditional domain-based takedowns by utilizing Tox, an encrypted peer-to-peer (P2P) messaging network, for its command-and-control (C2) communications. Because the C2 channel does not rely on a fixed domain or server address, operators can move the controller by simply copying a Tox save file, allowing clients to follow without needing a new domain.

The infection chain typically begins with a ClickFix lure. Attackers host a webpage, often on Cloudflare Workers, that impersonates a DocuSign signature request. The page displays a fake verification prompt claiming that “Verification is handled by Cloudflare” and instructs the user to paste a specific code into their terminal to access the document. This command retrieves and executes code via a Cloudflare Quick Tunnel, bypassing the browser’s standard download processes. While the lure may present macOS-style commands, the discovered payload is a 3.4 MB 64-bit Windows executable.

Entities

Cloudflare · DocuSign · Tox · Varonis Threat Labs