Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issues › Volume 342, Issue 4 › IT Vendor News › Varonis

Meet AvisLoader: A Windows Loader Built to Outlast a Takedown

Varonis, Wednesday, September 23rd, 2026

Varonis Threat Labs found a new Windows loader, AvisLoader, that uses encrypted P2P messaging to resist takedowns.

Varonis Threat Labs discovered AvisLoader, a new Windows malware loader found on an exposed staging server alongside a ClickFix phishing lure and its command center.

The attack begins with a fake DocuSign verification page that tricks visitors into pasting and running an attacker-supplied command, which retrieves code from a Cloudflare Quick Tunnel address.

AvisLoader's distinguishing feature is using Tox, an encrypted peer-to-peer messaging network, for command-and-control, making the channel independent of any fixed domain or server.

This lets operators move the controller to a new server simply by copying its Tox save file, complicating traditional domain-based takedowns.

more →  ·  More from Varonis →