Meet AvisLoader: A Windows Loader Built to Outlast a Takedown
AvisLoader is a newly discovered Windows malware loader that uses the Tox encrypted peer-to-peer messaging network for command-and-control communications, making traditional domain-based takedowns ineffective. The infection begins with a ClickFix social engineering technique, where victims are tricked into copying and executing malicious commands disguised as document verification steps. The loader is delivered through Cloudflare infrastructure and includes various stealth capabilities such as shortcut modification for persistence, UAC bypass attempts via UACME method 41, and process-hiding functionality through API hooking. Operators manage infected systems through a web-based Command Center that enables client management, task configuration, and payload distribution over the Tox network. The malware's architecture allows operators to maintain control by simply copying their Tox save file when relocating infrastructure, with clients automatically following without requiring domain updates.
AI Analysis
Technical Summary
AvisLoader is a newly discovered Windows malware loader that leverages the Tox encrypted peer-to-peer messaging network for its command-and-control communications, rendering traditional domain-based takedown strategies ineffective. Infection begins with a ClickFix social engineering tactic, where victims are deceived into copying and running malicious commands disguised as document verification steps. The loader is distributed via Cloudflare infrastructure and incorporates multiple stealth features such as shortcut modification to maintain persistence, attempts to bypass User Account Control (UAC) using UACME method 41, and process hiding through API hooking. Operators manage infected hosts through a web-based Command Center that facilitates client management, task configuration, and payload distribution over the Tox network. This architecture enables operators to maintain control by simply copying their Tox save file when moving infrastructure, with infected clients automatically following without requiring domain updates.
Potential Impact
The malware enables persistent and stealthy control over infected Windows systems, evading traditional domain-based takedown efforts due to its use of the Tox peer-to-peer network for command-and-control. It can bypass UAC protections and hide its processes, increasing the difficulty of detection and removal. The infection vector relies on social engineering, potentially leading to unauthorized execution of malicious commands by victims. The architecture allows operators to maintain long-term control and flexibility in relocating their infrastructure without disrupting infected clients.
Mitigation Recommendations
No official patch or remediation is indicated for this malware loader. Mitigation should focus on user education to recognize and avoid the ClickFix social engineering technique, restricting execution of untrusted commands, and monitoring for indicators of compromise such as the provided file hashes. Endpoint protection solutions should be updated to detect behaviors associated with UAC bypass, shortcut modification, and API hooking. Network defenses should consider the possibility of Tox peer-to-peer traffic for command-and-control. Since the malware uses Cloudflare infrastructure for delivery, monitoring and filtering suspicious traffic from such sources may help. There is no vendor advisory or patch available; organizations should apply layered detection and prevention controls accordingly.
Indicators of Compromise
- hash: 35dd164a7f5d8b42b9870c7009f7425b1c8cb771280c9e6c525e09f3dd13c2cc
- hash: cd1e835f52e5f55279dcdf3857e11bc9298ea6caa88eb214ea2d40ff5d38b5f5
- hash: f0a6870cb774a55775eda15fd39e8a17eb3169d5b9365186dae8edff07ff3975
Meet AvisLoader: A Windows Loader Built to Outlast a Takedown
Description
AvisLoader is a newly discovered Windows malware loader that uses the Tox encrypted peer-to-peer messaging network for command-and-control communications, making traditional domain-based takedowns ineffective. The infection begins with a ClickFix social engineering technique, where victims are tricked into copying and executing malicious commands disguised as document verification steps. The loader is delivered through Cloudflare infrastructure and includes various stealth capabilities such as shortcut modification for persistence, UAC bypass attempts via UACME method 41, and process-hiding functionality through API hooking. Operators manage infected systems through a web-based Command Center that enables client management, task configuration, and payload distribution over the Tox network. The malware's architecture allows operators to maintain control by simply copying their Tox save file when relocating infrastructure, with clients automatically following without requiring domain updates.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
AvisLoader is a newly discovered Windows malware loader that leverages the Tox encrypted peer-to-peer messaging network for its command-and-control communications, rendering traditional domain-based takedown strategies ineffective. Infection begins with a ClickFix social engineering tactic, where victims are deceived into copying and running malicious commands disguised as document verification steps. The loader is distributed via Cloudflare infrastructure and incorporates multiple stealth features such as shortcut modification to maintain persistence, attempts to bypass User Account Control (UAC) using UACME method 41, and process hiding through API hooking. Operators manage infected hosts through a web-based Command Center that facilitates client management, task configuration, and payload distribution over the Tox network. This architecture enables operators to maintain control by simply copying their Tox save file when moving infrastructure, with infected clients automatically following without requiring domain updates.
Potential Impact
The malware enables persistent and stealthy control over infected Windows systems, evading traditional domain-based takedown efforts due to its use of the Tox peer-to-peer network for command-and-control. It can bypass UAC protections and hide its processes, increasing the difficulty of detection and removal. The infection vector relies on social engineering, potentially leading to unauthorized execution of malicious commands by victims. The architecture allows operators to maintain long-term control and flexibility in relocating their infrastructure without disrupting infected clients.
Defensive Guidance
No official patch or remediation is indicated for this malware loader. Mitigation should focus on user education to recognize and avoid the ClickFix social engineering technique, restricting execution of untrusted commands, and monitoring for indicators of compromise such as the provided file hashes. Endpoint protection solutions should be updated to detect behaviors associated with UAC bypass, shortcut modification, and API hooking. Network defenses should consider the possibility of Tox peer-to-peer traffic for command-and-control. Since the malware uses Cloudflare infrastructure for delivery, monitoring and filtering suspicious traffic from such sources may help. There is no vendor advisory or patch available; organizations should apply layered detection and prevention controls accordingly.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.varonis.com/blog/meet-avisloader-a-windows-loader-built-to-outlast-a-takedown"]
- Pulse Id
- 6ab40d6887e7e948c6a09d80
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash35dd164a7f5d8b42b9870c7009f7425b1c8cb771280c9e6c525e09f3dd13c2cc | — | |
hashcd1e835f52e5f55279dcdf3857e11bc9298ea6caa88eb214ea2d40ff5d38b5f5 | — | |
hashf0a6870cb774a55775eda15fd39e8a17eb3169d5b9365186dae8edff07ff3975 | — |
Threat ID: 6ab4306bf7a7c54106430c4e
Added to database: 09/23/2026, 20:02:51 UTC
Last enriched: 09/23/2026, 20:19:41 UTC
Last updated: 09/24/2026, 01:51:29 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.