Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
From the same panel, attackers can send shell commands to selected computers. | The page then asks the visitor to paste a code into a terminal... When executed, the command retrieves and runs code outside the browser's normal download process.
A separate dynamic-link library (DLL), hmn_hook.dll, provides process-hiding functionality. It hooks NtQuerySystemInformation ... and filters a specified process name from the results.
The web-based AvisLoader Command Center gives attackers a list of infected computers and details such as their location, hardware, antivirus software and administrator status.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A 64-bit Windows loader delivered through a fake DocuSign ClickFix page. It statically links c-toxcore to use the Tox P2P network for resilient command-and-control, provides operators with system reconnaissance, remote shell-command execution, and additional-file delivery. It is designed to persist by modifying desktop and taskbar shortcuts; recovered components also include a possible UAC-bypass utility and a DLL capable of concealing selected processes.
Windows loader delivered through ClickFix social-engineering lures. It uses the Tox P2P protocol for encrypted command-and-control and payload delivery, incorporates shortcut-modification persistence artifacts, and its command center supports host profiling, shell-command tasking, and file distribution. Recovered companion components include a UAC-bypass helper and a DLL capable of filtering process names from NtQuerySystemInformation results, though successful deployment of those functions was not confirmed.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.