Socprime Emerging Malware Threats: AvisLoader and SmartApeSG Campaigns
Article Content
- •AvisLoader uses Tox P2P for C2 communication, enhancing its resilience.
- •SmartApeSG campaign delivers RAT and MeshAgent via ClickFix social engineering.
- •Organizations should enhance user training and monitor for suspicious activity.
Two recent cybersecurity threats have been identified, AvisLoader and SmartApeSG, both leveraging ClickFix social engineering tactics. AvisLoader is a Windows malware loader utilizing the Tox P2P network for command-and-control communication, often distributed via DocuSign-themed lures. SmartApeSG delivers a Remote Access Trojan (RAT) and MeshAgent through similar ClickFix schemes, employing password-protected ZIP archives for distribution. Both campaigns exploit user trust and require organizations to enhance user training and endpoint monitoring. Security teams are advised to monitor for suspicious Cloudflare activity and unauthorized execution of remote access tools. The ongoing threat landscape indicates a growing reliance on decentralized communication methods by attackers. Organizations must remain vigilant and implement robust detection and response strategies to mitigate these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track AvisLoader in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…