logo

Tracking PavinLoader across ClickFix and fake download campaigns

ID: f569f1be-dc36-5e8e-8824-ea16cf7f3981

STIX ID: report--f569f1be-dc36-5e8e-8824-ea16cf7f3981

Feed Name: Malwarebytes Blog

Threat Score
78/100

Date Published: 2026-08-24

Date Updated: 2026-08-25

...
...

This report analyzes PavinLoader, a heavily obfuscated multi-stage .NET loader observed across several campaigns (RenPy, ClickFix, fake software downloads) that uses EtherHiding (blockchain-based C2 discovery), MSBuild/.csproj/.bat abuse, and trojanized .NET DLLs to deliver payloads including Amatera Stealer; the analysis details distribution methods, stage functionality (loader, EtherHiding loader, anti-analysis DLL, PE loader), anti-analysis and obfuscation techniques, and provides IOCs (SHA-256 hashes, IPs, domains, and URLs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.