Researchers linked PavinLoader, a multi-stage .NET malware loader, to several intrusion chains that used ClickFix lures, fake software downloads, and malicious RenPy packages to infect victims. Across the campaigns, operators relied on trojanized and heavily obfuscated .NET DLLs, along with abuse of MSBuild through .csproj and .bat files, to execute later stages while complicating analysis and detection.
The loader retrieved command-and-control details using EtherHiding, including Binance Smart Chain RPC calls to pull infrastructure data from blockchain-hosted content, and then fetched additional payloads. In observed cases, PavinLoader delivered Amatera Stealer and at times HijackLoader, while also using anti-analysis and anti-forensics measures such as AMSI/ETW-related evasion strings, virtualization checks, locale filtering, and infrastructure-provider checks; shared artifacts and builder-like scripts led researchers to assess that it may be operated as a Loader-as-a-Service, though no commercial panel or offering was confirmed.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
Malwarebytes published an analysis tying together PavinLoader activity across malicious RenPy, ClickFix, and fake software download campaigns. The report detailed the loader's multi-stage architecture, MSBuild abuse, trojanized .NET DLLs, and EtherHiding-based C2 retrieval.
By correlating shared artifacts such as a VirusTotal item reused across more than 200 files and builder-like scripts containing comments like "EDIT HERE," researchers assessed that PavinLoader may be operated as a Loader-as-a-Service. The report notes this was not confirmed as a commercial offering.
Beyond Amatera Stealer, researchers also observed PavinLoader infections delivering other payloads, including HijackLoader. This showed the loader was being used to deploy multiple malware families on compromised systems.
The analysis found PavinLoader reused in fake software download campaigns, including cases where Dropbox was used to fetch the malware. This expanded the known delivery methods beyond RenPy and ClickFix lures.
Another campaign variant used BAT files with fake build-report comments, relaunched itself through conhost.exe with the --headless option, and then executed MSBuild on the BAT file. In the analyzed sample, the loader DLL was rebuilt by concatenating and decoding four Base64-encoded variables.
Researchers observed a ClickFix infection chain delivering an MSI named Installer_57be78.msi, which contained a legitimate MSBuild executable, a .csproj file, and a trojanized DotNetZip.dll used as the loader. The package abused MSBuild's UsingTask and related mechanisms to execute the malicious .NET component.
The reporting states that in a previously analyzed malicious RenPy campaign, PavinLoader was used in the infection chain and ultimately delivered Amatera Stealer. This establishes an earlier observed use of the loader before the newly discussed ClickFix and fake-download activity.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 30 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcemalware.news
Open sourcemalwarebytes.com
Open sourcecyberowi.pl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.