PavinLoader Uses ClickFix and Fake Downloads to Deploy Amatera Stealer via Blockchain C2
ID: aa3e59c0-6039-5407-bc9b-871297a77538
STIX ID: report--aa3e59c0-6039-5407-bc9b-871297a77538
Feed Name: GBHackers
Threat Score
PavinLoader is a multi-stage .NET loader deployed via fake CAPTCHAs, malicious installers, and game/mod lures that abuses MSBuild and trojanized .NET libraries to execute layered, obfuscated payloads; it uses EtherHiding (blockchain-resolved C2) to fetch XOR-encoded payloads and includes extensive anti-analysis checks, with observed deployments delivering Amatera stealer and associated IOCs (file hashes and IPs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
