top of page

AvisLoader Uses Tox Peer-to-Peer Messaging to Resist Domain Takedowns

2 hours ago
2 min read

A newly documented Windows malware loader uses the encrypted Tox peer-to-peer messaging network for command and control, making it less dependent on domains that defenders can seize or block.


Varonis Threat Labs discovered AvisLoader on an exposed staging server alongside a ClickFix lure, supporting tools and a web-based command center. The loader was also advertised for sale on a cybercrime forum, according to the researchers.


The observed delivery chain used a fake document-signing page hosted on Cloudflare Workers. Visitors were instructed to copy and run a supposed verification command, which retrieved code from a Cloudflare Quick Tunnel address. This ClickFix pattern moves execution outside the browser's normal download flow and relies on the user to launch the command.

Once installed, AvisLoader communicates as a Tox client. Because the operator's identity can persist across servers, defenders cannot disable the channel simply by taking down one conventional command-and-control domain.


Varonis found controls for issuing shell commands, selecting victims by location and hardware, and staging additional files for delivery.


The recovered toolkit also contained shortcut-persistence code, a helper referencing a known User Account Control bypass and a DLL capable of hiding a named process. Varonis cautioned that the files do not prove every capability was successfully deployed.


Security teams can still detect the surrounding behavior. Varonis recommends investigating document pages that ask users to paste commands, unfamiliar workers.dev or trycloudflare.com activity, unexpected Tox traffic, modified desktop shortcuts and references to the VLCAssistant launcher.


The full AvisLoader analysis includes MITRE ATT&CK mappings and file hashes. The discovery shows why resilient peer-to-peer infrastructure must be paired with endpoint telemetry: even when the control channel moves, the loader still leaves execution, persistence and process artifacts on the host.

bottom of page