AvisLoader is a sophisticated Windows malware loader specifically designed to maintain its operation even after its command servers are taken offline. This characteristic makes it notably challenging to counter simply by deactivating the malicious domains it uses.
The Deceptive Entry Point
The malware initially entices victims through a counterfeit document-signing webpage that misleadingly requests users to execute a command, transforming a seemingly legitimate action into a potential security threat. This page falsely claims to require a manual verification handled by a security provider but instead deploys malicious code via a temporary tunnel, bypassing standard browser download paths.
Mirroring strategies seen in previous ClickFix campaigns, the malware persuades users to trigger the infection themselves. Varonis Threat Labs discovered AvisLoader on an exposed server, complete with lures, supporting files, and a control dashboard, as reported to Cyber Security News (CSN).
Resilient Communication Methods
Unlike typical malware that relies on a fixed domain, AvisLoader employs encrypted peer-to-peer messaging for command and file retrieval, enhancing its resilience against domain takedowns. This approach was revealed by Varonis when they found the malware advertised on a cybercrime forum.
AvisLoader leverages the Tox messaging network, allowing computers to communicate as peers, which avoids dependency on a static control address. This adaptability means that even if the controller’s location is changed, it can continue to operate by copying its Tox save file, maintaining continuity of control over infected machines.
Methods of Detection and Prevention
Despite its adaptability, AvisLoader is not invisible. Security teams can detect abnormal network connections, which may indicate the presence of this malware. The malware uses Cloudflare tunnels for initial code delivery and Tox for subsequent command exchanges, urging defenders to differentiate between download paths and control channels.
Security researchers advise vigilance over altered desktop and taskbar shortcuts, which may be exploited to launch malware unnoticed. They also recommend investigating unusual peer-to-peer traffic and scrutinizing document or verification pages instructing command pasting.
Indicators of compromise, such as specific file hashes and domain associations, should be monitored closely to mitigate potential threats. These precautions are essential in maintaining IT security and safeguarding against evolving malware like AvisLoader.
