New Windows Malware Built to Survive Takedowns With a Hidden P2P Command Network
Varonis uncovers AvisLoader, a Windows loader using encrypted Tox P2P for takedown-resistant C2, delivered via ClickFix DocuSign lures.
Varonis Threat Labs identified AvisLoader, a 3.4 MB 64-bit Windows loader statically linking c-toxcore, which receives commands and follow-on payloads over the encrypted Tox peer-to-peer network instead of fixed C2 infrastructure. Infection starts with a fake DocuSign ClickFix page instructing victims to paste an attacker-supplied command that fetches code through a Cloudflare Quick Tunnel. Bundled components include auto.exe implementing UACME method 41 UAC bypass via ICMLuaUtil, shortcut hijacking of desktop and taskbar shortcuts, and hmn_hook.dll hooking NtQuerySystemInformation to hide processes. An operator command center tracks endpoint metadata and queues shell commands or payload transfers matching hardware, geography, or privilege criteria.