AvisLoader Windows Malware Uses Tox P2P for Command-and-Control

Summary
Varonis researchers analyzed AvisLoader, a Windows loader delivered through a ClickFix lure. It uses encrypted Tox peer-to-peer messaging for command-and-control and includes artifacts for shortcut persistence, elevation bypass, and process hiding.
Key points
- A DocuSign-themed ClickFix page hosted on Cloudflare Workers prompted users to paste and run a command that retrieved code through a Cloudflare Quick Tunnel.
- Researchers recovered a 64-bit Windows loader that uses the Tox protocol for peer-to-peer command-and-control, avoiding reliance on a fixed domain or server address.
- The loader contains artifacts for persistence through modified desktop and taskbar shortcuts; successful deployment of the mechanism was not confirmed.
- Bundled tools reference a UAC bypass technique and process-list hiding, but the analysis did not confirm successful elevation or that the hiding library was deployed.
- The Command Center interface supports client management, shell tasks, and file staging for delivery over Tox.
- Varonis recommends investigating suspicious paste-and-run prompts, remote-code execution, unexpected Tox traffic, modified shortcuts, and the recovered file indicators.
Article Details
- Attack Vectors
- A DocuSign-themed ClickFix page on Cloudflare Workers asks visitors to paste and run an attacker-supplied command. The command retrieves and executes code from a Cloudflare Quick Tunnel address.
- AvisLoader artifacts indicate a mechanism for modifying desktop and taskbar shortcuts to launch the loader before opening the intended application. Execution through a modified shortcut was not established.
- A bundled auto.exe helper references UACME method 41 for a UAC bypass; successful elevation was not confirmed.
- A bundled hmn_hook.dll hooks NtQuerySystemInformation to filter a specified process name from results. Its deployment was not confirmed.
- AvisLoader uses Tox for command-and-control communications. Its recovered Command Center supports shell tasks and file delivery to clients over Tox; successful file transfers were not confirmed.
- Defensive Notes
- Treat document-signing or verification pages that ask users to paste commands into a terminal or Windows Run dialog as suspicious.
- Investigate unfamiliar workers.dev and trycloudflare.com addresses in document-signing lures or download-and-execute commands, using page content and surrounding activity for context because both domains support legitimate services.
- Monitor shells and script interpreters that retrieve and execute remote code after visits to suspicious pages, and check the same device for unexpected Tox or other peer-to-peer traffic.
- Hunt for modified desktop and taskbar shortcuts, associated .backup files, and references to VLCAssistant. Investigate matches for auto.exe or hmn_hook.dll alongside possible elevation attempts or process-list hooks.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| SHA256 | 35dd164a7f5d8b42b9870c7009f7425b1c8cb771280c9e6c525e09f3dd13c2cc | SHA-256 of 78324.exe, the AvisLoader Windows client. |
| SHA256 | cd1e835f52e5f55279dcdf3857e11bc9298ea6caa88eb214ea2d40ff5d38b5f5 | SHA-256 of hmn_hook.dll, the bundled process-hiding library. |
| SHA256 | f0a6870cb774a55775eda15fd39e8a17eb3169d5b9365186dae8edff07ff3975 | SHA-256 of auto.exe, the bundled elevation-bypass helper. |
MITRE ATT&CK
T1014 · RootkitThe bundled hmn_hook.dll hooks NtQuerySystemInformation to filter a specified process name from returned results; deployment was not confirmed.T1071 · Application Layer ProtocolAvisLoader incorporates c-toxcore for Tox-based command-and-control communications.T1105 · Ingress Tool TransferThe recovered Command Center offers file delivery to clients over Tox; successful transfers were not confirmed.T1204.004 · Malicious Copy and PasteThe ClickFix lure instructs visitors to paste and run an attacker-supplied command.T1547.009 · Shortcut ModificationAvisLoader artifacts indicate modification of desktop and taskbar shortcuts to launch malware when opened; boot or logon execution was not established.T1548.002 · Bypass User Account ControlThe bundled auto.exe helper references UACME method 41 for a UAC bypass; successful elevation was not confirmed.
Malware
Vendors
Products
Cloudflare Quick TunnelWhat lands on the clipboard is a command that retrieves and runs code from a Cloudflare Quick Tunnel address on trycloudflare.com.Cloudflare WorkersThe specific ClickFix lure we found alongside AvisLoader was hosted on Cloudflare Workers and made to look like a DocuSign signing request.Data Security PlatformVaronis' Data Security Platform uses behavioral analytics to flag abnormal activity that matches these techniques, including unexpected process lineage from a browser or script interpreter, privilege escalation, and theMicrosoft WindowsVaronis Threat Labs recently discovered AvisLoader, a new Windows loader named after the Latin word for bird.Varonis MDDRVaronis MDDR pairs that detection with an expert team that triages and contains incidents like this one.