Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Tracking PavinLoader across ClickFix and fake download campaigns

0
Medium
Published: 08/25/2026 (08/25/2026, 07:12:42 UTC)
Source: AlienVault OTX General

Description

A sophisticated multi-stage loader dubbed PavinLoader has been identified across multiple distribution campaigns including ClickFix attacks, fake software downloads, and malicious RenPy games. The loader employs heavily obfuscated .NET DLLs, abuses legitimate Windows tools like MSBuild, and utilizes EtherHiding technique to retrieve command-and-control domains via blockchain. The infection chain consists of four main stages: a Loader DLL performing anti-forensics, an EtherHiding Loader obtaining C2 infrastructure, an Anti-Analysis DLL checking for virtualized environments, and a PE Loader delivering final payloads including Amatera Stealer. Evidence suggests PavinLoader may be offered as a Loader-as-a-Service, with common artifacts found across over 200 related files. The campaigns demonstrate sophisticated evasion techniques including custom obfuscation, API hashing, and extensive anti-analysis checks targeting virtualized environments and specific geographic regions.

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.malwarebytes.com/blog/threat-intel/2026/08/tracking-pavinloader-across-clickfix-and-fake-download-campaigns"]
Adversary
null
Pulse Id
6a8d406a23f75e32b69c2029
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainmore-arpc.icu
domainrpcsecnoweb.pro
domainkelemet.shop
domainnexahub.lat
domainstellar-minds.cfd
domainperfectverified.com
domaincatalyst-pro.lat
domaintwigoamwu.cfd
domainpinnacle-labs.lat
domainfimwoglea.shop
domainvelodium.lat
domainecho-systems.cfd
domaincyberowi.pl

Ip

ValueDescriptionCopy
ip93.152.224.75

Hash

ValueDescriptionCopy
hashbdf313a019e025ebf58ccef4619444ee70e661bd444e0644ebeabd8f5caad14c
hashe3830f5747e3f46537d217124d80c9f3bb4d89f8d4f5138dce69ee54ea4fb6b9
hasha4f03272cf96732dc9f58bb466d16f358e7f50d46dba30526a9fbebfec11717b
hashbf04160dd1ce3571e0eb6d6dda1713c788797b5599399d4a93665a757eec376e
hash54fa8083c05334aa360256fbbb0ca901ce7e244a0359dd664cae78977371ec91
hashc1ea6d169565c70ac5d812e73483814929e9b3548ead6633595937e71a334adb
hash001337488c32d8610c2aef6f9330acca825f0afacd071bf6ebfc06b5a1a69f09
hash2837099af431e9afee76ce5e6ab5cb86bedce06e31c22be46250cb453cfdb978
hash252c5a3d150275013f52b4820097d7163ced4aa2f1be0fca032f8a5017673816
hash0c9c64b7383ec249bcf6271a4b73206d94de130ca401d16ab77fe01e5193a312
hash6700f62e1a3b33340cd678c388ecc8bac2e5943c0627df5d1b99b879c3ca42c9
hash0c7311a8b1e93a551f8c91f5d3a173d7
hash2b224ccf0bbfc74d82202517c0e8c61a
hash323cf31ab7b4cb38da910d7df2a89b17
hash4397133d1c4b4f8dce5dc87bbe112073
hash52a9c1f6d03a656cac5872daf45f2a5a
hash98044793c18598442a796d77da57bc20
hashadbc54fdfc0f623130c62f3e9699089b
hashb2fe819dbb5a0e02d50973cc055373b8
hashc40224524a925451dadcad4452f8d4e8
hash06cae19840cb14f053f0cbbec7329942f81167bf
hash2f0b481d8f4075cf9b57e91777c0fd7b2e29975d
hash3d71ec0a4f419ad1e347617de8b7d7a7589e43f1
hash8c20118ae06e279c58ff0bb4e9b15f45b9868b65
hash98a4ddec118de21e573709787b5e6cda66d6f8f5
hash9e064619a2e36b2c3cdd5c38ad2f919165859604
hashba1cf6e507981d355cdb395547259fde25590b81
hashcfd1eeaaa81c4133378190cc1d34379bd7f8afa9
hashe25982db20dc1272ea5a1d41c8c86c734c2e15df

Threat ID: 6a8d73d1acd9273b490ff983

Added to database: 08/25/2026, 10:52:01 UTC

Last updated: 08/25/2026, 16:29:26 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses