Meet AvisLoader: A Windows Loader Built to Outlast a Takedown
Varonis, Wednesday, September 23rd, 2026
Varonis Threat Labs found a new Windows loader, AvisLoader, that uses encrypted P2P messaging to resist takedowns.
Varonis Threat Labs discovered AvisLoader, a new Windows malware loader found on an exposed staging server alongside a ClickFix phishing lure and its command center.
The attack begins with a fake DocuSign verification page that tricks visitors into pasting and running an attacker-supplied command, which retrieves code from a Cloudflare Quick Tunnel address.
AvisLoader's distinguishing feature is using Tox, an encrypted peer-to-peer messaging network, for command-and-control, making the channel independent of any fixed domain or server.
This lets operators move the controller to a new server simply by copying its Tox save file, complicating traditional domain-based takedowns.