< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Cybersecurity researchers identify resilient malware and crypto-stealing operations

Security researchers have identified two distinct malware operations targeting Windows users. Varonis Threat Labs discovered AvisLoader, a malware loader that utilizes the encrypted Tox peer-to-peer messaging network for command and control. This method makes the malware more resilient to traditional defense measures, as operators can maintain control even if specific domains are seized or blocked. The loader often uses a ClickFix pattern, where victims are tricked via fake document-signing pages into running commands that retrieve malicious code.

Separately, Netskope Threat Labs analyzed an underground operation known as Underground, which has successfully drained approximately $100,000 in cryptocurrency. This operation employs an Aotera/Tedy loader to inject a Vidar-class stealer into Windows processes. The malware specifically targets web browsers like Chrome and Edge by injecting scripts directly into active sessions. This allows the stealer to access signed-in cryptocurrency exchange accounts without writing the malicious stage to the disk, helping it evade detection.

Entities

Chrome · Cloudflare · Netskope Threat Labs · Tox · Varonis Threat Labs