< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 4 sources · 7 days · First seen · Last updated

AvisLoader malware deployment

Overview

Cybersecurity researchers have identified AvisLoader, a Windows malware loader designed to evade traditional domain-based takedowns. The malware utilizes the Tox encrypted peer-to-peer (P2P) messaging network for its command-and-control (C2) communications. This architecture allows operators to move controllers by simply copying a Tox save file, ensuring clients can follow without requiring a new domain.

The infection process frequently employs a ‘ClickFix’ lure. In this scenario, attackers host webpages—often via Cloudflare Workers—that impersonate DocuSign signature requests. Victims are presented with a fake verification prompt and instructed to paste specific code into their terminal. This command executes code via a Cloudflare Quick Tunnel, bypassing standard browser download processes to deliver a Windows executable payload.

Entities

Varonis Threat Labs · Tox · Cloudflare · Chrome · DocuSign

Timeline

  1. [TECHNOLOGY] 3 sources
    Cybersecurity researchers identify resilient malware and crypto-stealing operations

    Researchers have uncovered two malware operations: AvisLoader, which uses the Tox P2P network for resilient command and control, and an underground crypto-stealing operation that has drained $100,000.

  2. [TECHNOLOGY] 2 sources
    AvisLoader malware uses P2P network to evade takedowns

    Researchers have discovered AvisLoader, a new Windows malware loader that uses the Tox P2P network to evade domain takedowns and employs ClickFix lures disguised as DocuSign requests.

Sources

cybernoz.com · enterprisesecuritytech.com · hackernoon.com · netskope.com