Tracking PavinLoader across ClickFix and fake download campaigns
Description
A sophisticated multi-stage loader dubbed PavinLoader has been identified across multiple distribution campaigns including ClickFix attacks, fake software downloads, and malicious RenPy games. The loader employs heavily obfuscated .NET DLLs, abuses legitimate Windows tools like MSBuild, and utilizes EtherHiding technique to retrieve command-and-control domains via blockchain. The infection chain consists of four main stages: a Loader DLL performing anti-forensics, an EtherHiding Loader obtaining C2 infrastructure, an Anti-Analysis DLL checking for virtualized environments, and a PE Loader delivering final payloads including Amatera Stealer. Evidence suggests PavinLoader may be offered as a Loader-as-a-Service, with common artifacts found across over 200 related files. The campaigns demonstrate sophisticated evasion techniques including custom obfuscation, API hashing, and extensive anti-analysis checks targeting virtualized environments and specific geographic regions.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
PavinLoader is a multi-stage .NET-based loader that operates through four main components: a Loader DLL performing anti-forensics, an EtherHiding Loader that retrieves C2 infrastructure via blockchain, an Anti-Analysis DLL that detects virtualized environments, and a PE Loader that delivers payloads such as Amatera Stealer. It abuses legitimate Windows tools like MSBuild for execution and employs custom obfuscation and API hashing to evade detection. The loader is distributed through multiple campaigns including ClickFix attacks, fake software downloads, and malicious RenPy games. Evidence suggests it is offered as a Loader-as-a-Service, indicated by common artifacts across a large number of related files. The malware uses sophisticated evasion techniques including anti-analysis, anti-forensics, and geographic targeting.
Potential Impact
The malware enables attackers to deliver and execute payloads such as the Amatera Stealer, which can compromise sensitive information. Its advanced evasion techniques make detection and analysis difficult, increasing the risk of persistent infections. The use of blockchain-based C2 retrieval (EtherHiding) complicates takedown efforts and attribution. The loader's abuse of legitimate Windows tools and anti-analysis capabilities can hinder incident response and forensic investigations.
Defensive Guidance
No official patch or remediation is indicated. Since this is malware distributed via multiple campaigns, mitigation should focus on detection and prevention through endpoint protection solutions capable of identifying obfuscated .NET loaders and suspicious use of MSBuild. Network monitoring for blockchain-based C2 communications and behavioral analysis to detect anti-forensics and anti-analysis techniques may help. Incident responders should be aware of the multi-stage infection chain and use specialized tools to analyze obfuscated DLLs. There is no vendor advisory indicating a fix; patch status is not yet confirmed — check vendor advisories for updates.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.malwarebytes.com/blog/threat-intel/2026/08/tracking-pavinloader-across-clickfix-and-fake-download-campaigns"]
- Pulse Id
- 6a8d406a23f75e32b69c2029
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainmore-arpc.icu | — | |
domainrpcsecnoweb.pro | — | |
domainkelemet.shop | — | |
domainnexahub.lat | — | |
domainstellar-minds.cfd | — | |
domainperfectverified.com | — | |
domaincatalyst-pro.lat | — | |
domaintwigoamwu.cfd | — | |
domainpinnacle-labs.lat | — | |
domainfimwoglea.shop | — | |
domainvelodium.lat | — | |
domainecho-systems.cfd | — | |
domaincyberowi.pl | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip93.152.224.75 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashbdf313a019e025ebf58ccef4619444ee70e661bd444e0644ebeabd8f5caad14c | — | |
hashe3830f5747e3f46537d217124d80c9f3bb4d89f8d4f5138dce69ee54ea4fb6b9 | — | |
hasha4f03272cf96732dc9f58bb466d16f358e7f50d46dba30526a9fbebfec11717b | — | |
hashbf04160dd1ce3571e0eb6d6dda1713c788797b5599399d4a93665a757eec376e | — | |
hash54fa8083c05334aa360256fbbb0ca901ce7e244a0359dd664cae78977371ec91 | — | |
hashc1ea6d169565c70ac5d812e73483814929e9b3548ead6633595937e71a334adb | — | |
hash001337488c32d8610c2aef6f9330acca825f0afacd071bf6ebfc06b5a1a69f09 | — | |
hash2837099af431e9afee76ce5e6ab5cb86bedce06e31c22be46250cb453cfdb978 | — | |
hash252c5a3d150275013f52b4820097d7163ced4aa2f1be0fca032f8a5017673816 | — | |
hash0c9c64b7383ec249bcf6271a4b73206d94de130ca401d16ab77fe01e5193a312 | — | |
hash6700f62e1a3b33340cd678c388ecc8bac2e5943c0627df5d1b99b879c3ca42c9 | — | |
hash0c7311a8b1e93a551f8c91f5d3a173d7 | — | |
hash2b224ccf0bbfc74d82202517c0e8c61a | — | |
hash323cf31ab7b4cb38da910d7df2a89b17 | — | |
hash4397133d1c4b4f8dce5dc87bbe112073 | — | |
hash52a9c1f6d03a656cac5872daf45f2a5a | — | |
hash98044793c18598442a796d77da57bc20 | — | |
hashadbc54fdfc0f623130c62f3e9699089b | — | |
hashb2fe819dbb5a0e02d50973cc055373b8 | — | |
hashc40224524a925451dadcad4452f8d4e8 | — | |
hash06cae19840cb14f053f0cbbec7329942f81167bf | — | |
hash2f0b481d8f4075cf9b57e91777c0fd7b2e29975d | — | |
hash3d71ec0a4f419ad1e347617de8b7d7a7589e43f1 | — | |
hash8c20118ae06e279c58ff0bb4e9b15f45b9868b65 | — | |
hash98a4ddec118de21e573709787b5e6cda66d6f8f5 | — | |
hash9e064619a2e36b2c3cdd5c38ad2f919165859604 | — | |
hashba1cf6e507981d355cdb395547259fde25590b81 | — | |
hashcfd1eeaaa81c4133378190cc1d34379bd7f8afa9 | — | |
hashe25982db20dc1272ea5a1d41c8c86c734c2e15df | — |
Threat ID: 6a8d73d1acd9273b490ff983
Added to database: 08/25/2026, 10:52:01 UTC
Last enriched: 09/25/2026, 01:48:01 UTC
Last updated: 10/04/2026, 06:48:18 UTC
Views: 177
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.