PavinLoader Abuses MSBuild and Trojanized .NET DLLs in Multi-Stage Malware Attacks
ID: e3ccf000-2eef-51e3-8d5f-79f70b743947
STIX ID: report--e3ccf000-2eef-51e3-8d5f-79f70b743947
Feed Name: Cyber Press
Researchers have uncovered expanded use of PavinLoader — a multi-stage malware loader leveraging legitimate Windows build tools, trojanized .NET libraries, heavy obfuscation, and blockchain-based EtherHiding for C2 resolution — observed delivering payloads such as the Amatera infostealer via fake CAPTCHAs, pirated installers, and malicious game installers; the report describes the loader's MSBuild-based execution chain, anti-analysis checks, observed TLDs and infrastructure patterns, and provides two SHA-256 IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
