Skip to main content

Meet AvisLoader: A Windows Loader Built to Outlast a Takedown

0
Medium
Published: 09/23/2026 (09/23/2026, 17:33:28 UTC)
Source: AlienVault OTX General

Description

AvisLoader is a newly discovered Windows malware loader that uses the Tox encrypted peer-to-peer messaging network for command-and-control communications, making traditional domain-based takedowns ineffective. The infection begins with a ClickFix social engineering technique, where victims are tricked into copying and executing malicious commands disguised as document verification steps. The loader is delivered through Cloudflare infrastructure and includes various stealth capabilities such as shortcut modification for persistence, UAC bypass attempts via UACME method 41, and process-hiding functionality through API hooking. Operators manage infected systems through a web-based Command Center that enables client management, task configuration, and payload distribution over the Tox network. The malware's architecture allows operators to maintain control by simply copying their Tox save file when relocating infrastructure, with clients automatically following without requiring domain updates.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/23/2026, 20:19:41 UTC

Technical Analysis

AvisLoader is a newly discovered Windows malware loader that leverages the Tox encrypted peer-to-peer messaging network for its command-and-control communications, rendering traditional domain-based takedown strategies ineffective. Infection begins with a ClickFix social engineering tactic, where victims are deceived into copying and running malicious commands disguised as document verification steps. The loader is distributed via Cloudflare infrastructure and incorporates multiple stealth features such as shortcut modification to maintain persistence, attempts to bypass User Account Control (UAC) using UACME method 41, and process hiding through API hooking. Operators manage infected hosts through a web-based Command Center that facilitates client management, task configuration, and payload distribution over the Tox network. This architecture enables operators to maintain control by simply copying their Tox save file when moving infrastructure, with infected clients automatically following without requiring domain updates.

Potential Impact

The malware enables persistent and stealthy control over infected Windows systems, evading traditional domain-based takedown efforts due to its use of the Tox peer-to-peer network for command-and-control. It can bypass UAC protections and hide its processes, increasing the difficulty of detection and removal. The infection vector relies on social engineering, potentially leading to unauthorized execution of malicious commands by victims. The architecture allows operators to maintain long-term control and flexibility in relocating their infrastructure without disrupting infected clients.

Defensive Guidance

No official patch or remediation is indicated for this malware loader. Mitigation should focus on user education to recognize and avoid the ClickFix social engineering technique, restricting execution of untrusted commands, and monitoring for indicators of compromise such as the provided file hashes. Endpoint protection solutions should be updated to detect behaviors associated with UAC bypass, shortcut modification, and API hooking. Network defenses should consider the possibility of Tox peer-to-peer traffic for command-and-control. Since the malware uses Cloudflare infrastructure for delivery, monitoring and filtering suspicious traffic from such sources may help. There is no vendor advisory or patch available; organizations should apply layered detection and prevention controls accordingly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.varonis.com/blog/meet-avisloader-a-windows-loader-built-to-outlast-a-takedown"]
Pulse Id
6ab40d6887e7e948c6a09d80

Indicators of Compromise

Hash

ValueDescriptionCopy
hash35dd164a7f5d8b42b9870c7009f7425b1c8cb771280c9e6c525e09f3dd13c2cc
hashcd1e835f52e5f55279dcdf3857e11bc9298ea6caa88eb214ea2d40ff5d38b5f5
hashf0a6870cb774a55775eda15fd39e8a17eb3169d5b9365186dae8edff07ff3975

Threat ID: 6ab4306bf7a7c54106430c4e

Added to database: 09/23/2026, 20:02:51 UTC

Last enriched: 09/23/2026, 20:19:41 UTC

Last updated: 09/24/2026, 01:51:29 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses