AvisLoader Windows Malware Uses Tox P2P for Command-and-Control

· Original article ↗

Summary

Varonis researchers analyzed AvisLoader, a Windows loader delivered through a ClickFix lure. It uses encrypted Tox peer-to-peer messaging for command-and-control and includes artifacts for shortcut persistence, elevation bypass, and process hiding.

Key points

  • A DocuSign-themed ClickFix page hosted on Cloudflare Workers prompted users to paste and run a command that retrieved code through a Cloudflare Quick Tunnel.
  • Researchers recovered a 64-bit Windows loader that uses the Tox protocol for peer-to-peer command-and-control, avoiding reliance on a fixed domain or server address.
  • The loader contains artifacts for persistence through modified desktop and taskbar shortcuts; successful deployment of the mechanism was not confirmed.
  • Bundled tools reference a UAC bypass technique and process-list hiding, but the analysis did not confirm successful elevation or that the hiding library was deployed.
  • The Command Center interface supports client management, shell tasks, and file staging for delivery over Tox.
  • Varonis recommends investigating suspicious paste-and-run prompts, remote-code execution, unexpected Tox traffic, modified shortcuts, and the recovered file indicators.

Article Details

Attack Vectors
  • A DocuSign-themed ClickFix page on Cloudflare Workers asks visitors to paste and run an attacker-supplied command. The command retrieves and executes code from a Cloudflare Quick Tunnel address.
  • AvisLoader artifacts indicate a mechanism for modifying desktop and taskbar shortcuts to launch the loader before opening the intended application. Execution through a modified shortcut was not established.
  • A bundled auto.exe helper references UACME method 41 for a UAC bypass; successful elevation was not confirmed.
  • A bundled hmn_hook.dll hooks NtQuerySystemInformation to filter a specified process name from results. Its deployment was not confirmed.
  • AvisLoader uses Tox for command-and-control communications. Its recovered Command Center supports shell tasks and file delivery to clients over Tox; successful file transfers were not confirmed.
Defensive Notes
  • Treat document-signing or verification pages that ask users to paste commands into a terminal or Windows Run dialog as suspicious.
  • Investigate unfamiliar workers.dev and trycloudflare.com addresses in document-signing lures or download-and-execute commands, using page content and surrounding activity for context because both domains support legitimate services.
  • Monitor shells and script interpreters that retrieve and execute remote code after visits to suspicious pages, and check the same device for unexpected Tox or other peer-to-peer traffic.
  • Hunt for modified desktop and taskbar shortcuts, associated .backup files, and references to VLCAssistant. Investigate matches for auto.exe or hmn_hook.dll alongside possible elevation attempts or process-list hooks.

Indicators of compromise

TypeIndicatorContext
SHA25635dd164a7f5d8b42b9870c7009f7425b1c8cb771280c9e6c525e09f3dd13c2ccSHA-256 of 78324.exe, the AvisLoader Windows client.
SHA256cd1e835f52e5f55279dcdf3857e11bc9298ea6caa88eb214ea2d40ff5d38b5f5SHA-256 of hmn_hook.dll, the bundled process-hiding library.
SHA256f0a6870cb774a55775eda15fd39e8a17eb3169d5b9365186dae8edff07ff3975SHA-256 of auto.exe, the bundled elevation-bypass helper.

MITRE ATT&CK

Malware

Vendors

Products

Tools

Related Articles