AvisLoader: New Windows Loader Uses Tox P2P Network for C2
Varonis Threat Labs discovered AvisLoader, a Windows malware loader that uses the encrypted Tox peer-to-peer network for command-and-control instead of a fixed domain, making takedowns harder. It is delivered via a fake DocuSign page on Cloudflare Workers using a ClickFix lure.
- The loader is a single 3.4 MB 64-bit executable with statically linked c-toxcore
- C2 has no fixed domain: the controller moves by copying its Tox save file
- Persistence targets desktop and taskbar shortcuts via a VBScript launcher named VLCAssistant
- A helper auto.exe references UACME method 41 for a UAC bypass
Read next
Security