logo

PavinLoader Abuses MSBuild and Trojanized .NET DLLs in Multi-Stage Malware Attacks

ID: e3ccf000-2eef-51e3-8d5f-79f70b743947

STIX ID: report--e3ccf000-2eef-51e3-8d5f-79f70b743947

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Varshini

...
...

Researchers have uncovered expanded use of PavinLoader — a multi-stage malware loader leveraging legitimate Windows build tools, trojanized .NET libraries, heavy obfuscation, and blockchain-based EtherHiding for C2 resolution — observed delivering payloads such as the Amatera infostealer via fake CAPTCHAs, pirated installers, and malicious game installers; the report describes the loader's MSBuild-based execution chain, anti-analysis checks, observed TLDs and infrastructure patterns, and provides two SHA-256 IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.