Last seven days
- First activity
- Aug 24, 2026
- Last activity
- Aug 24, 2026
- Feed role
- C2
- Host form
- 0 IP / 14 hostnames
C2 tracking
Derp observations, rolling seven-day window
MITRE ATT&CK
Reporting
Researchers linked PavinLoader, a multi-stage .NET malware loader, to several intrusion chains that used ClickFix lures, fake software downloads, and malicious RenPy packages to infect victims. Across the campaigns, operators relied on trojanized and heavily obfuscated .NET DLLs, along with abuse of MSBuild through .csproj and .bat files, to execute later stages while complicating analysis and detection. The loader retrieved command-and-control details using EtherHiding, including Binance Smart Chain RPC calls to pull infrastructure data from blockchain-hosted content, and then fetched additional payloads. In observed cases, PavinLoader delivered Amatera Stealer and at times HijackLoader, while also using anti-analysis and anti-forensics measures such as AMSI/ETW-related evasion strings, virtualization checks, locale filtering, and infrastructure-provider checks; shared artifacts and builder-like scripts led researchers to assess that it may be operated as a Loader-as-a-Service, though no commercial panel or offering was confirmed.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.