A newly discovered Windows loader is rewriting the rules of command-and-control resilience by ditching domains altogether in favor of an encrypted peer-to-peer messaging network, making the usual takedown playbook largely ineffective.
Varonis Threat Labs uncovered the malware, dubbed AvisLoader, on an exposed staging server that also housed its delivery lure, support tools, and full administrative panel.
The infection begins with a ClickFix-style social engineering trick: a fake DocuSign verification page, hosted on Cloudflare Workers, tells visitors that “verification is handled by Cloudflare” and instructs them to paste a code into a terminal.
New AvisLoader Windows Malware
That pasted command actually fetches malicious code from a Cloudflare Quick Tunnel address, bypassing normal browser download protections entirely.
What makes AvisLoader notable isn’t the delivery mechanism; ClickFix lures are increasingly common, but what happens after execution is. Instead of phoning home to a fixed domain or IP, the loader statically links c-toxcore, the reference implementation of the Tox protocol, turning the infected machine into a peer on an encrypted P2P network.

A cybercrime forum listing for the tool reportedly boasts that operators can relocate their entire controller by simply copying a Tox save file, with infected clients reconnecting automatically no domain re-registration, no new C2 infrastructure to burn.
The 3.4 MB, 64-bit executable ships with seventeen decoy sections named after packers like Themida, VMProtect, and UPX, none actually executable, apparently designed to throw off automated packer detection.
For persistence, it targets desktop and taskbar shortcuts, backs them up, and hijacks them via a VBScript launcher referencing “VLCAssistant,” so the malware fires silently while the original app still opens normally.
A companion helper, auto.exe, implements UACME method 41 to attempt a UAC bypass through the ICMLuaUtil COM interface, though Varonis notes it doesn’t confirm successful elevation.
A separate DLL, hmn_hook.dll, hooks the NtQuerySystemInformation function to potentially scrub a chosen process from process lists, rootkit-style concealment that wasn’t confirmed as actively deployed against AvisLoader itself.
The recovered “AvisLoader Command Center” web panel reveals a polished operator experience: live counts of online/offline clients, a world map, and a table listing each victim’s hostname, country, hardware, installed antivirus, and admin status.
A Tasks tab lets operators target clients by machine specs or location and queue shell commands for execution the moment a device reconnects, all routed over Tox.
Despite its resilient C2 design, AvisLoader leaves plenty of forensic footprints. Varonis recommends treating any signing or verification page that demands a pasted terminal command as an immediate red flag, scrutinizing unfamiliar workers.dev and trycloudflare.com links, and hunting for unexpected Tox traffic alongside modified shortcuts, .backup files, and references to VLCAssistant.
MITRE ATT&CK Mapping
| Technique ID | Technique Name | Evidence |
|---|---|---|
| T1204.004 | User Execution: Malicious Copy and Paste | ClickFix lure instructs pasting attacker code |
| T1547.009 | Shortcut Modification | Backup and hijack of desktop/taskbar shortcuts |
| T1548.002 | Bypass UAC | auto.exe implements UACME method 41 |
| T1014 | Rootkit | hmn_hook.dll hooks NtQuerySystemInformation |
| T1071 | Application Layer Protocol | Tox-based C2 via c-toxcore |
| T1105 | Ingress Tool Transfer | Command Center file delivery over Tox |
Key Indicators of Compromise
| File | SHA-256 (truncated) | Role |
|---|---|---|
| 78324.exe | 35dd164a7f5d8b42b9870c7009f7425… | AvisLoader Windows client |
| auto.exe | f0a6870cb774a55775eda15fd39e8a1… | UAC-bypass helper |
| hmn_hook.dll | cd1e835f52e5f55279dcdf3857e11bc… | Process-hiding library |
AvisLoader is a reminder that resilience in modern malware no longer hinges on bulletproof hosting it hinges on borrowing legitimate, encrypted infrastructure that defenders can’t simply seize.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.