Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 4 sources · 7 days · First seen · Last updated
AvisLoader malware deployment
Overview
Cybersecurity researchers have identified AvisLoader, a Windows malware loader designed to evade traditional domain-based takedowns. The malware utilizes the Tox encrypted peer-to-peer (P2P) messaging network for its command-and-control (C2) communications. This architecture allows operators to move controllers by simply copying a Tox save file, ensuring clients can follow without requiring a new domain.
The infection process frequently employs a ‘ClickFix’ lure. In this scenario, attackers host webpages—often via Cloudflare Workers—that impersonate DocuSign signature requests. Victims are presented with a fake verification prompt and instructed to paste specific code into their terminal. This command executes code via a Cloudflare Quick Tunnel, bypassing standard browser download processes to deliver a Windows executable payload.
Entities
Varonis Threat Labs · Tox · Cloudflare · Chrome · DocuSign
Timeline
-
[TECHNOLOGY] 3 sourcesCybersecurity researchers identify resilient malware and crypto-stealing operations
Researchers have uncovered two malware operations: AvisLoader, which uses the Tox P2P network for resilient command and control, and an underground crypto-stealing operation that has drained $100,000.
-
[TECHNOLOGY] 2 sourcesAvisLoader malware uses P2P network to evade takedowns
Researchers have discovered AvisLoader, a new Windows malware loader that uses the Tox P2P network to evade domain takedowns and employs ClickFix lures disguised as DocuSign requests.
Sources
cybernoz.com · enterprisesecuritytech.com · hackernoon.com · netskope.com