Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
As we saw in our previous analysis of these ClickFix campaigns, the associated PowerShell scripts change frequently. We found several versions in this activity, including both obfuscated and unobfuscated scripts.
The MSI CustomAction executes the BAT script with: cmd.exe /c C:\Users\{USER}\AppData\Local\Conexant\lite_bootstrap_2.1.7\updater_8219.cmd /launched
The .NET DLLs associated with PavinLoader are heavily obfuscated using control-flow flattening, custom bytecode, indirect calls through calli / ldftn , string encryption with different algorithms, API hashing and delegates, redundant methods, and junk code and strings.
Resolves APIs using API hashing and GetDelegateForFunctionPointer()
The C++-compiled PE disguises itself as WPA.exe (Windows Performance Analyzer).
The Loader DLL is reconstructed by concatenating and decoding four Base64-encoded variables.
PavinLoader uses legitimate Windows tools alongside malicious .NET files to run several stages of malware.
This DLL is responsible for performing several anti-analysis checks.
The loader obtains the system’s LCID using GetKeyboardLayoutList() and compares it against more than 17 languages, including Russian, Ukrainian, Belarusian, and Armenian. | It also performs extensive system reconnaissance, including enumerating registry keys and calling Win32 APIs such as GetSystemFirmwareTable() and EnumSystemFirmwareTables() to identify virtualized environments.
It also performs extensive system reconnaissance, including enumerating registry keys and calling Win32 APIs such as GetSystemFirmwareTable() and EnumSystemFirmwareTables() to identify virtualized environments.
This DLL is responsible for performing several anti-analysis checks.
The loader obtains the system’s LCID using GetKeyboardLayoutList() and compares it against more than 17 languages, including Russian, Ukrainian, Belarusian, and Armenian. | It also performs extensive system reconnaissance, including enumerating registry keys and calling Win32 APIs such as GetSystemFirmwareTable() and EnumSystemFirmwareTables() to identify virtualized environments.
More than 100 URLs belonging to legitimate services are also decrypted and used to generate HTTP requests and network noise.
EtherHiding to obtain the C2 domain, followed by HTTP requests using paths such as assets/{two random words}.json to retrieve subsequent stages.
EtherHiding to obtain the C2 domain, followed by HTTP requests using paths such as assets/{two random words}.json to retrieve subsequent stages.
Changes network settings, including disabling TLS certificate validation and setting the default system proxy
It also uses EtherHiding, a technique that uses a blockchain to hide information about its infrastructure, to find the server from which it should retrieve additional malware.
The EtherHiding Loader has two main functions: obtaining the C2 domain through EtherHiding, and downloading and loading subsequent stages from that C2. | These include multi-stage infection chains involving heavily obfuscated and trojanized .NET DLLs; abuse of MSBuild, .csproj , and .bat files to execute them; and EtherHiding to retrieve the command-and-control (C2) domain.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage .NET loader used across malicious RenPy, ClickFix, and fake software download campaigns. It abuses trojanized .NET DLLs, MSBuild, .csproj and .bat files, uses EtherHiding to retrieve C2 infrastructure from blockchain data, performs anti-forensics and anti-analysis steps, and delivers follow-on payloads including stealers and other malware.
A multi-stage .NET loader used across multiple campaigns. It abuses MSBuild, .csproj, BAT files, trojanized .NET DLLs, and EtherHiding to obtain C2 infrastructure and deliver additional payloads. Its stages include a loader DLL, an EtherHiding loader, an anti-analysis DLL, and a PE loader.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.