logo

PavinLoader Uses ClickFix and Fake Downloads to Deploy Amatera Stealer via Blockchain C2

ID: aa3e59c0-6039-5407-bc9b-871297a77538

STIX ID: report--aa3e59c0-6039-5407-bc9b-871297a77538

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Mayura Kathir

...
...

PavinLoader is a multi-stage .NET loader deployed via fake CAPTCHAs, malicious installers, and game/mod lures that abuses MSBuild and trojanized .NET libraries to execute layered, obfuscated payloads; it uses EtherHiding (blockchain-resolved C2) to fetch XOR-encoded payloads and includes extensive anti-analysis checks, with observed deployments delivering Amatera stealer and associated IOCs (file hashes and IPs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.