AvisLoader hides its C2 in the Tox peer-to-peer network
AvisLoader takes commands over Tox, so seizing a server does not cut it off, and it hijacks desktop shortcuts to persist. How it works and how to hunt it.
By Yaali. September 29, 2026, 6 min read, Threat intel, Phishing.
Varonis Threat Labs published an analysis of AvisLoader on September 23, a Windows malware loader that receives its commands through Tox, the encrypted peer-to-peer messaging network. A loader's job is to get a foothold and then fetch whatever the operator wants to run next. Most loaders call home to a domain or IP address that defenders can block, sinkhole or seize. AvisLoader has no such address to take away.
Researchers found it on an exposed staging server, together with the lure, helper tools and the operator's web command center. Victims arrive through a DocuSign-themed ClickFix page on Cloudflare Workers that asks them to paste a command, which pulls code from a Cloudflare Quick Tunnel address on trycloudflare.com. No victim count has been published. Any Windows fleet where users can paste commands into a terminal is a possible target, and detection has to happen on the endpoint and in network flow data, since blocking a domain will not stop it.

How Tox command and control works
Tox is an open source messenger with no central server. Each user is identified by a public key, and clients find each other through a distributed hash table (DHT), a lookup table spread across every node on the network. A new client joins by contacting a bootstrap node, a publicly listed Tox node that introduces it to other peers. The reference bootstrap daemon listens on UDP 33445 and offers TCP relays on ports 443, 3389 and 33445 for clients that cannot make direct UDP connections. Once two peers find each other, their messages are end-to-end encrypted.
AvisLoader statically links c-toxcore, the reference Tox library, into a single 3.4 MB 64-bit executable. The build still carries the developer path C:\Users\dev\Desktop\c-toxcore. The infected machine becomes a Tox peer, and the operator is just another Tox identity on the network, reached by public key.
A seller advertising AvisLoader on a cybercrime forum claimed the controller can be moved by copying its Tox save file, the file that holds the identity's key pair, and that clients follow it without needing a domain. Seizing the machine the controller runs on does not end the botnet if the operator has a copy of that file somewhere else. The command center dashboard lists each infected client with hostname, country, CPU, GPU, antivirus product and administrator status, and lets the operator pick clients by those fields, send shell commands and stage files for delivery over Tox.
The executable also tries to confuse analysis tools. Its manifest requests asInvoker, so it runs with the rights of whoever started it and triggers no User Account Control (UAC) prompt. Its section table has seventeen extra sections of identical size named after packers such as Themida, VMProtect, Enigma and UPX. None is executable; they exist to mislead tools that identify packers by section name.
Shortcut hijack persistence
AvisLoader stays on the machine by modifying shortcuts on the desktop and the taskbar. Varonis found shortcut-backup strings in the binary and a VBScript launcher associated with the name VLCAssistant. When the user clicks a modified shortcut, the malware runs first and then starts the application the user expected, so nothing looks wrong. MITRE ATT&CK tracks this as T1547.009, Shortcut Modification.
This persistence is easy to miss for two reasons. It creates no Run key, service or scheduled task, which is where most autostart checks look. It also fires only when the user opens an app they use every day, at a moment when Explorer is starting programs anyway.
Taskbar pins are ordinary .lnk files under %APPDATA%\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar, writable by the user without admin rights. The original shortcuts appear to be kept as .backup files, which gives defenders a clean artefact to search for.
The helpers: UAC bypass and process hiding
Two more files sat on the staging server. auto.exe references method 41 from UACME, a public collection of UAC bypass techniques. Method 41 calls the auto-elevated CMSTPLUA COM object through its ICMLuaUtil interface. That object runs inside dllhost.exe at high integrity, so a command started through its ShellExec method gets admin rights without a prompt, as long as the user is a local administrator.
hmn_hook.dll hooks NtQuerySystemInformation, the Windows function that returns the process list, and filters a chosen process name out of the results. Task Manager and many simple tools then stop showing the loader. A user-mode hook like this does not blind an EDR sensor that collects process events from the kernel.
What to hunt for

No vulnerability is involved, so this is detection and configuration work.
Tox traffic. Few businesses have a reason to run Tox. The public bootstrap list is published as JSON at https://nodes.tox.chat/json. Load those IP addresses into a firewall alias or a SIEM lookup and alert on any internal host that talks to them, on UDP 33445 in particular. Relays on TCP 443 and 3389 blend in with normal HTTPS and RDP, so match on destination address, not port. Alerting on outbound UDP 33445 to any destination is cheap to add. On the endpoint, look for an executable with a numeric-only name, such as the recovered 78324.exe, that opens many outbound UDP connections shortly after first running.
Shortcut targets. Enumerate every .lnk on user desktops, the Public desktop and the taskbar folder above, and record each target path and arguments (the WScript.Shell COM object's CreateShortcut method reads them in PowerShell). A browser or Office shortcut whose target is wscript.exe, a .vbs file or an executable in a user-writable folder is suspect. Search those folders for .backup files sitting next to shortcuts, and for any file or script containing the string VLCAssistant. Sysmon event ID 11 (FileCreate) on .lnk files in those folders catches future changes.
Pasted commands. The AvisLoader lure asks for a terminal, so the Group Policy that removes the Run dialog does not cover it on its own. The PowerShell and Windows Terminal controls in our TerminalFix write-up apply here unchanged. For AvisLoader specifically, alert on a shell process whose command line or network activity reaches trycloudflare.com or an unfamiliar workers.dev host. Legitimate staff rarely use Quick Tunnels, so blocking *.trycloudflare.com at the web proxy is worth testing.
Files. Search EDR telemetry for the SHA-256 hashes Varonis published:
78324.exe, the loader:35dd164a7f5d8b42b9870c7009f7425b1c8cb771280c9e6c525e09f3dd13c2ccauto.exe, the UAC bypass:f0a6870cb774a55775eda15fd39e8a17eb3169d5b9365186dae8edff07ff3975hmn_hook.dll, the process hider:cd1e835f52e5f55279dcdf3857e11bc9298ea6caa88eb214ea2d40ff5d38b5f5
Also look for dllhost.exe started with /Processid:{3E5FC7F9-9A51-4367-9063-A120244FBEC7} followed by a new high-integrity child process, the usual trace of the ICMLuaUtil bypass. Setting UAC to "Always notify" and removing local admin rights from daily-use accounts takes that bypass away.
If you find it. Isolate the host. Restore modified shortcuts from a known-good copy, or check the target of each .backup file before putting it back. Delete the VBScript launcher and the loader. Because the operator could push any shell command or file over Tox, treat the machine as fully compromised: collect what ran after infection, rotate credentials cached on it, and reimage if you cannot account for everything.
Why a takedown misses this
Defenders have long relied on seizing domains and servers to cut botnets off. Tox, like other peer-to-peer networks, gives a loader operator the same reach with nothing central to seize. That shifts the work to egress rules that deny peer-to-peer protocols by default and to endpoint telemetry that records shortcut changes and outbound UDP.
Our security operations team hunts for this kind of persistence and unusual egress, and safeguarding and hardening reviews cover UAC, local admin rights and outbound firewall policy. Open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: Varonis Threat Labs, Hackread, Cyber Security News, SOC Prime, GBHackers, OffSeq Threat Radar, Tox bootstrap node status, toxcore bootstrap daemon config, UACME method 41 analysis, Taskbar pinned shortcuts location.
Read next
- Placeholder domains in AI agent skills now serve scams
- PREY-0058: fake IT calls that steal Microsoft 365 sessions
- Astrana Health breach: vishing spoofed its own number
Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.