Last seven days
- First activity
- Sep 4, 2026
- Last activity
- Sep 4, 2026
- Feed role
- C2
- Host form
- 0 IP / 4 hostnames
PavinLoader is a multi-stage .NET malware loader used in Windows intrusion chains associated with ClickFix social-engineering lures, fake software downloads, and malicious game installers.
Profile source: Mallory opens in a new tabPavinLoader
PavinLoader is a multi-stage .NET malware loader used in Windows intrusion chains associated with ClickFix social-engineering lures, fake software downloads, and malicious game installers. It is designed to execute staged components, evade analysis, recover command-and-control information dynamically, and deliver follow-on malware. Observed payloads include Amatera Stealer and, in other cases, additional loaders such as HijackLoader, indicating that PavinLoader functions as a flexible delivery mechanism rather than a single-purpose implant.
Infection chains attributed to PavinLoader rely on user execution rather than software exploitation. Campaigns have used fake verification or CAPTCHA-style pages that trick victims into running commands, as well as trojanized installers and software packages. Execution commonly abuses trusted Windows components and build tooling, especially MSBuild, project files, batch scripts, and conhost, to reconstruct and launch malicious .NET assemblies while blending into legitimate system activity. Trojanized .NET libraries have been used as loader stages, and some variants rebuild payload components from encoded data at runtime.
The malware employs multiple stages with distinct roles. Initial loader components perform string decryption, API resolution, network-setting changes, and anti-analysis checks before loading subsequent modules. A later stage uses EtherHiding techniques to obtain command-and-control infrastructure indirectly through blockchain-related requests instead of embedding it directly in the sample. Additional modules perform extensive anti-analysis and environment screening, including virtualization and sandbox detection, locale and regional filtering, and checks intended to avoid execution on hosted or researcher-controlled systems. Final stages load and execute PE payloads delivered from remote infrastructure.
PavinLoader demonstrates strong defense-evasion tradecraft. Reported behaviors include heavy obfuscation, anti-forensics measures, certificate-validation bypassing, proxy configuration changes, API hashing, and references consistent with AMSI and ETW interference. The malware has been observed using staged JSON-based retrieval for later payloads and can support delivery of credential- and data-theft malware. In documented cases, downstream objectives included theft of passwords, browser data, cryptocurrency-wallet information, and other files.
The repeated reuse of PavinLoader across multiple lure formats and campaign clusters suggests an operator model capable of supporting different intrusion workflows, and it has been assessed as a possible loader-as-a-service offering, although public commercialization has not been confirmed. High-confidence observations place it in ongoing Windows-focused social-engineering campaigns where it serves as an adaptable malware delivery platform.
C2 tracking
Derp observations, rolling seven-day window
MITRE ATT&CK
Reporting
Researchers linked PavinLoader, a multi-stage .NET malware loader, to several intrusion chains that used ClickFix lures, fake software downloads, and malicious RenPy packages to infect victims. Across the campaigns, operators relied on trojanized and heavily obfuscated .NET DLLs, along with abuse of MSBuild through .csproj and .bat files, to execute later stages while complicating analysis and detection. The loader retrieved command-and-control details using EtherHiding, including Binance Smart Chain RPC calls to pull infrastructure data from blockchain-hosted content, and then fetched additional payloads. In observed cases, PavinLoader delivered Amatera Stealer and at times HijackLoader, while also using anti-analysis and anti-forensics measures such as AMSI/ETW-related evasion strings, virtualization checks, locale filtering, and infrastructure-provider checks; shared artifacts and builder-like scripts led researchers to assess that it may be operated as a Loader-as-a-Service, though no commercial panel or offering was confirmed.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.