Skip to content

PavinLoader

PavinLoader is a multi-stage .NET malware loader used in Windows intrusion chains associated with ClickFix social-engineering lures, fake software downloads, and malicious game installers.

Profile source: Mallory opens in a new tab

PavinLoader

Family profile

PavinLoader is a multi-stage .NET malware loader used in Windows intrusion chains associated with ClickFix social-engineering lures, fake software downloads, and malicious game installers. It is designed to execute staged components, evade analysis, recover command-and-control information dynamically, and deliver follow-on malware. Observed payloads include Amatera Stealer and, in other cases, additional loaders such as HijackLoader, indicating that PavinLoader functions as a flexible delivery mechanism rather than a single-purpose implant.

Infection chains attributed to PavinLoader rely on user execution rather than software exploitation. Campaigns have used fake verification or CAPTCHA-style pages that trick victims into running commands, as well as trojanized installers and software packages. Execution commonly abuses trusted Windows components and build tooling, especially MSBuild, project files, batch scripts, and conhost, to reconstruct and launch malicious .NET assemblies while blending into legitimate system activity. Trojanized .NET libraries have been used as loader stages, and some variants rebuild payload components from encoded data at runtime.

The malware employs multiple stages with distinct roles. Initial loader components perform string decryption, API resolution, network-setting changes, and anti-analysis checks before loading subsequent modules. A later stage uses EtherHiding techniques to obtain command-and-control infrastructure indirectly through blockchain-related requests instead of embedding it directly in the sample. Additional modules perform extensive anti-analysis and environment screening, including virtualization and sandbox detection, locale and regional filtering, and checks intended to avoid execution on hosted or researcher-controlled systems. Final stages load and execute PE payloads delivered from remote infrastructure.

PavinLoader demonstrates strong defense-evasion tradecraft. Reported behaviors include heavy obfuscation, anti-forensics measures, certificate-validation bypassing, proxy configuration changes, API hashing, and references consistent with AMSI and ETW interference. The malware has been observed using staged JSON-based retrieval for later payloads and can support delivery of credential- and data-theft malware. In documented cases, downstream objectives included theft of passwords, browser data, cryptocurrency-wallet information, and other files.

The repeated reuse of PavinLoader across multiple lure formats and campaign clusters suggests an operator model capable of supporting different intrusion workflows, and it has been assessed as a possible loader-as-a-service offering, although public commercialization has not been confirmed. High-confidence observations place it in ongoing Windows-focused social-engineering campaigns where it serves as an adaptable malware delivery platform.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 4, 2026
Last activity
Sep 4, 2026
Feed role
C2
Host form
0 IP / 4 hostnames

Leading locations

  • US4

Leading providers

  • Cloudflare, Inc.4

Infrastructure traits

  • Anycast 4
  • Hosting 4

MITRE ATT&CK

PavinLoader in ATT&CK

29 distinct techniques

Reporting

Research mentioning PavinLoader

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.