PavinWide is a .NET anti-analysis malware component used in multi-stage Windows infection chains that culminate in the deployment of Amatera Stealer. It has been observed as one of several secondary payloads downloaded after an initial loader sequence that abuses the legitimate Ren’Py engine, BAT scripting, and MSBuild-based execution. Within this chain, PavinWide functions as an anti-analysis stage intended to hinder sandboxing, malware inspection, or other defensive examination before later payloads are decrypted and executed.
PavinWide has been associated with campaigns that lure victims with fake game, mod, crack, and software downloads distributed through fraudulent download portals, malicious hosting pages, and file-sharing services. These campaigns present decoy installation interfaces while malicious activity proceeds in the background. In the observed sequence, PavinWide is delivered alongside other supporting components including GollopDevest, a loader/downloader stage that uses EtherHiding to retrieve command-and-control information, and LanoseThrip, a native DLL responsible for decrypting and loading Amatera Stealer.
The malware is part of a broader staged intrusion workflow characterized by defense evasion and post-exploitation preparation. Although PavinWide itself is specifically identified as an anti-analysis DLL rather than the final payload, its role supports the reliable execution of downstream credential and data theft operations carried out by Amatera Stealer. The activity cluster using this component has targeted Windows users seeking pirated or unofficial software and gaming-related content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Composant .NET anti-analyse utilisé comme payload additionnel dans la chaîne d’infection.
An anti-analysis DLL downloaded in later stages of the infection chain.
An anti-analysis DLL downloaded in later stages of the infection chain to hinder analysis and support execution of subsequent payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.