Skip to main content

Tracking PavinLoader across ClickFix and fake download campaigns

0
Medium
Published: 08/25/2026 (08/25/2026, 07:12:42 UTC)
Source: AlienVault OTX General

Description

A sophisticated multi-stage loader dubbed PavinLoader has been identified across multiple distribution campaigns including ClickFix attacks, fake software downloads, and malicious RenPy games. The loader employs heavily obfuscated .NET DLLs, abuses legitimate Windows tools like MSBuild, and utilizes EtherHiding technique to retrieve command-and-control domains via blockchain. The infection chain consists of four main stages: a Loader DLL performing anti-forensics, an EtherHiding Loader obtaining C2 infrastructure, an Anti-Analysis DLL checking for virtualized environments, and a PE Loader delivering final payloads including Amatera Stealer. Evidence suggests PavinLoader may be offered as a Loader-as-a-Service, with common artifacts found across over 200 related files. The campaigns demonstrate sophisticated evasion techniques including custom obfuscation, API hashing, and extensive anti-analysis checks targeting virtualized environments and specific geographic regions.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/25/2026, 01:48:01 UTC

Technical Analysis

PavinLoader is a multi-stage .NET-based loader that operates through four main components: a Loader DLL performing anti-forensics, an EtherHiding Loader that retrieves C2 infrastructure via blockchain, an Anti-Analysis DLL that detects virtualized environments, and a PE Loader that delivers payloads such as Amatera Stealer. It abuses legitimate Windows tools like MSBuild for execution and employs custom obfuscation and API hashing to evade detection. The loader is distributed through multiple campaigns including ClickFix attacks, fake software downloads, and malicious RenPy games. Evidence suggests it is offered as a Loader-as-a-Service, indicated by common artifacts across a large number of related files. The malware uses sophisticated evasion techniques including anti-analysis, anti-forensics, and geographic targeting.

Potential Impact

The malware enables attackers to deliver and execute payloads such as the Amatera Stealer, which can compromise sensitive information. Its advanced evasion techniques make detection and analysis difficult, increasing the risk of persistent infections. The use of blockchain-based C2 retrieval (EtherHiding) complicates takedown efforts and attribution. The loader's abuse of legitimate Windows tools and anti-analysis capabilities can hinder incident response and forensic investigations.

Defensive Guidance

No official patch or remediation is indicated. Since this is malware distributed via multiple campaigns, mitigation should focus on detection and prevention through endpoint protection solutions capable of identifying obfuscated .NET loaders and suspicious use of MSBuild. Network monitoring for blockchain-based C2 communications and behavioral analysis to detect anti-forensics and anti-analysis techniques may help. Incident responders should be aware of the multi-stage infection chain and use specialized tools to analyze obfuscated DLLs. There is no vendor advisory indicating a fix; patch status is not yet confirmed — check vendor advisories for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.malwarebytes.com/blog/threat-intel/2026/08/tracking-pavinloader-across-clickfix-and-fake-download-campaigns"]
Pulse Id
6a8d406a23f75e32b69c2029

Indicators of Compromise

Domain

ValueDescriptionCopy
domainmore-arpc.icu
—
domainrpcsecnoweb.pro
—
domainkelemet.shop
—
domainnexahub.lat
—
domainstellar-minds.cfd
—
domainperfectverified.com
—
domaincatalyst-pro.lat
—
domaintwigoamwu.cfd
—
domainpinnacle-labs.lat
—
domainfimwoglea.shop
—
domainvelodium.lat
—
domainecho-systems.cfd
—
domaincyberowi.pl
—

Ip

ValueDescriptionCopy
ip93.152.224.75
—

Hash

ValueDescriptionCopy
hashbdf313a019e025ebf58ccef4619444ee70e661bd444e0644ebeabd8f5caad14c
—
hashe3830f5747e3f46537d217124d80c9f3bb4d89f8d4f5138dce69ee54ea4fb6b9
—
hasha4f03272cf96732dc9f58bb466d16f358e7f50d46dba30526a9fbebfec11717b
—
hashbf04160dd1ce3571e0eb6d6dda1713c788797b5599399d4a93665a757eec376e
—
hash54fa8083c05334aa360256fbbb0ca901ce7e244a0359dd664cae78977371ec91
—
hashc1ea6d169565c70ac5d812e73483814929e9b3548ead6633595937e71a334adb
—
hash001337488c32d8610c2aef6f9330acca825f0afacd071bf6ebfc06b5a1a69f09
—
hash2837099af431e9afee76ce5e6ab5cb86bedce06e31c22be46250cb453cfdb978
—
hash252c5a3d150275013f52b4820097d7163ced4aa2f1be0fca032f8a5017673816
—
hash0c9c64b7383ec249bcf6271a4b73206d94de130ca401d16ab77fe01e5193a312
—
hash6700f62e1a3b33340cd678c388ecc8bac2e5943c0627df5d1b99b879c3ca42c9
—
hash0c7311a8b1e93a551f8c91f5d3a173d7
—
hash2b224ccf0bbfc74d82202517c0e8c61a
—
hash323cf31ab7b4cb38da910d7df2a89b17
—
hash4397133d1c4b4f8dce5dc87bbe112073
—
hash52a9c1f6d03a656cac5872daf45f2a5a
—
hash98044793c18598442a796d77da57bc20
—
hashadbc54fdfc0f623130c62f3e9699089b
—
hashb2fe819dbb5a0e02d50973cc055373b8
—
hashc40224524a925451dadcad4452f8d4e8
—
hash06cae19840cb14f053f0cbbec7329942f81167bf
—
hash2f0b481d8f4075cf9b57e91777c0fd7b2e29975d
—
hash3d71ec0a4f419ad1e347617de8b7d7a7589e43f1
—
hash8c20118ae06e279c58ff0bb4e9b15f45b9868b65
—
hash98a4ddec118de21e573709787b5e6cda66d6f8f5
—
hash9e064619a2e36b2c3cdd5c38ad2f919165859604
—
hashba1cf6e507981d355cdb395547259fde25590b81
—
hashcfd1eeaaa81c4133378190cc1d34379bd7f8afa9
—
hashe25982db20dc1272ea5a1d41c8c86c734c2e15df
—

Threat ID: 6a8d73d1acd9273b490ff983

Added to database: 08/25/2026, 10:52:01 UTC

Last enriched: 09/25/2026, 01:48:01 UTC

Last updated: 10/04/2026, 06:48:18 UTC

Views: 177

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses