Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Tracking PavinLoader across ClickFix and fake download campaigns

released on 2026-08-25 @ 07:12:42 AM
A sophisticated multi-stage loader dubbed PavinLoader has been identified across multiple distribution campaigns including ClickFix attacks, fake software downloads, and malicious RenPy games. The loader employs heavily obfuscated .NET DLLs, abuses legitimate Windows tools like MSBuild, and utilizes EtherHiding technique to retrieve command-and-control domains via blockchain. The infection chain consists of four main stages: a Loader DLL performing anti-forensics, an EtherHiding Loader obtaining C2 infrastructure, an Anti-Analysis DLL checking for virtualized environments, and a PE Loader delivering final payloads including Amatera Stealer. Evidence suggests PavinLoader may be offered as a Loader-as-a-Service, with common artifacts found across over 200 related files. The campaigns demonstrate sophisticated evasion techniques including custom obfuscation, API hashing, and extensive anti-analysis checks targeting virtualized environments and specific geographic regions.