Podlipodcast player Webplayer

The Good Tech Companies

The Good Tech Companies

Meet AvisLoader: A Windows Loader Built to Outlast a Takedown

The Good Tech Companies · Sep 24, 2026 · 11:39

0:0011:39

Listen in the Podli app 🎧

Follow your favourite podcasts, listen offline and in the car with CarPlay and Android Auto, and always pick up where you left off. Free to try.

This story was originally published on HackerNoon at: https://hackernoon.com/meet-avisloader-a-windows-loader-built-to-outlast-a-takedown.
Discover how AvisLoader uses Tox peer-to-peer messaging for C2, ClickFix delivery, shortcut persistence, and payload distribution without fixed domains.
Check more stories related to undefined at: https://hackernoon.com/c/undefined. You can also check exclusive content about #avisloader-malware, #tox-peer-to-peer-malware, #windows-malware-loader, #clickfix-malware-campaign, #tox-based-c2-communication, #avisloader-varonis-threat-labs, #avisloader-tox-c2, #good-company, and more.

This story was written by: @varonis. Learn more about this writer by checking @varonis's about page, and for more stories, please visit hackernoon.com.

Varonis Threat Labs discovered AvisLoader, a Windows malware loader that uses the encrypted Tox peer-to-peer network for command-and-control communication and payload delivery. Found alongside a ClickFix lure and operator Command Center, the loader combines shortcut persistence, a bundled UAC bypass helper, and process-hiding functionality. Its Tox-based architecture makes domain-focused takedowns harder, while host activity provides additional detection opportunities for security teams.

Episodes: The Good Tech Companies

PodliGet the free Podli app
↓ App