$ techbeacon▋
Phishing

AvisLoader Malware Exploits ClickFix Lure and Tox Network for Stealthy Command‑and‑Control

AvisLoader Malware Exploits ClickFix Lure and Tox Network for Stealthy Command‑and‑Control

Varonis Threat Labs has identified a new Windows-based malware loader, dubbed AvisLoader, that leverages the Tox peer‑to‑peer network for its command‑and‑control (C2) communications while reaching victims through a deceptive ClickFix lure.

The analysis, first reported by Hackread, shows AvisLoader arriving as a seemingly innocuous ClickFix utility—a tool often associated with Windows system repair. Once executed, the loader establishes a covert channel over Tox, a decentralized messaging protocol originally designed for secure, encrypted chat. By using a P2P network instead of traditional centralized servers, the malware can evade many conventional detection methods that rely on known C2 domains or IP addresses.

Technical details reveal that AvisLoader drops additional payloads after the initial infection, allowing attackers to extend their foothold on compromised machines. The loader’s code is obfuscated, and its network traffic is disguised as legitimate Tox traffic, making it difficult for security products that focus on HTTP‑based C2 patterns to flag the activity. The use of Tox also provides resilience; even if some nodes are taken down, the remaining peers can continue to relay commands.

Security researchers note that the ClickFix lure is part of a broader trend where cybercriminals repurpose legitimate‑looking utilities to trick users into running malicious code. In many cases, the lure is distributed via phishing emails, malicious ads, or compromised software download sites. The combination of a trusted‑sounding name and a seemingly helpful function increases the likelihood that an unsuspecting user will grant the necessary permissions.

Varonis Threat Labs recommends that organizations reinforce endpoint protection by monitoring for unusual peer‑to‑peer traffic, especially on ports and protocols associated with Tox. Additionally, users should be educated to verify the source of any system‑maintenance tools before execution and to avoid downloading software from unverified repositories.

The discovery of AvisLoader underscores the evolving tactics of threat actors who blend legitimate technology with malicious intent to bypass defenses. As peer‑to‑peer networks gain traction among cybercriminals, security teams will need to adapt detection strategies beyond traditional signature‑based methods, incorporating behavioral analytics and network‑flow monitoring to spot the subtle anomalies introduced by loaders like AvisLoader.

Source: Hackread
Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related