# AvisLoader malware deployment

> Live situation record from CLSTR: https://clstr.news/situations/avisloader-malware-deployment
> Updated: 2026-09-30T06:23:45.000Z. Sources: 4. Developments: 2.

Cybersecurity researchers have identified AvisLoader, a Windows malware loader designed to evade traditional domain-based takedowns. The malware utilizes the Tox encrypted peer-to-peer (P2P) messaging network for its command-and-control (C2) communications. This architecture allows operators to move controllers by simply copying a Tox save file, ensuring clients can follow without requiring a new domain.

The infection process frequently employs a ‘ClickFix’ lure. In this scenario, attackers host webpages—often via Cloudflare Workers—that impersonate DocuSign signature requests. Victims are presented with a fake verification prompt and instructed to paste specific code into their terminal. This command executes code via a Cloudflare Quick Tunnel, bypassing standard browser download processes to deliver a Windows executable payload.

## Timeline

### 2026-09-30: Cybersecurity researchers identify resilient malware and crypto-stealing operations

Researchers have uncovered two malware operations: AvisLoader, which uses the Tox P2P network for resilient command and control, and an underground crypto-stealing operation that has drained $100,000.

3 sources. https://clstr.news/cluster/cybersecurity-researchers-identify-resilient-malware-and-crypto-stealing-operations

### 2026-09-24: AvisLoader malware uses P2P network to evade takedowns

Researchers have discovered AvisLoader, a new Windows malware loader that uses the Tox P2P network to evade domain takedowns and employs ClickFix lures disguised as DocuSign requests.

2 sources. https://clstr.news/cluster/avisloader-malware-uses-p2p-network-to-evade-takedowns

---
Cite as: AvisLoader malware deployment. CLSTR, https://clstr.news/situations/avisloader-malware-deployment
