Back to all lessons
Awareness Lessons
2 weeks ago

AvisLoader Exploits ClickFix Social Engineering and Tox P2P for Resilient C2

AvisLoader targets Windows users by leveraging a ClickFix social engineering lure, tricking users into executing malicious code under the guise of a legitimate fix or prompt. By routing command and control traffic through the Tox peer-to-peer network, the malware avoids traditional domain-based detection and takedown efforts, making it significantly harder for defenders to disrupt. This highlights how attackers are combining human manipulation with decentralized infrastructure to maximize resilience and evade conventional defenses. Organizations that lack user awareness training and robust outbound traffic monitoring are especially vulnerable to this class of threat.

Tactical Insight

Immediate actions

  • Train users to recognize and report ClickFix-style prompts that instruct them to paste or run scripts in PowerShell or the Run dialog.
  • Block or alert on outbound connections to known Tox network nodes and unusual peer-to-peer protocols at the perimeter firewall.
  • Deploy endpoint detection and response (EDR) tools configured to flag suspicious loader activity and unexpected process execution chains.

Long-term improvements

  • Implement application allowlisting to prevent unauthorized executables and scripts from running on Windows endpoints.
  • Enforce least-privilege principles so standard users cannot execute administrative commands triggered by social engineering lures.
  • Establish a formal security awareness program with phishing and social engineering simulations conducted at least quarterly.

Detection measures

  • Monitor and alert on anomalous outbound P2P traffic patterns or connections to non-standard ports using network traffic analysis tools.
  • Collect and centralize endpoint logs to detect loader behaviors such as in-memory execution, process injection, or unusual parent-child process relationships.
  • Integrate threat intelligence feeds that include indicators of compromise (IOCs) for AvisLoader and ClickFix campaigns into your SIEM.